Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
1738 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.49% | — | Amauri Wpmobile.appAI | 2/10/2026 | 2/10/2026 | The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate… | |
| Aplazada | Media (6.9) | 0.24% | — | Amauri IO Wpmobile APPAI | 30/9/2026 | 30/9/2026 | Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83. | |
| Aplazada | Alta (7.1) | 0.09% | — | Freshlightlab WP Mobile MenuAI | 30/9/2026 | 30/9/2026 | The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every… | |
| Aplazada | Alta (7.5) | 0.24% | — | Parla Auto Automotive Trading Limited Company Detawix Mobile WEB PortalAI | 29/9/2026 | 30/9/2026 | Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19. | |
| Aplazada | Alta (8.7) | 0.30% | — | BSV Wallet ToolboxAIBSV Wallet Toolbox ClientAIBSV Wallet Toolbox MobileAI | 24/9/2026 | 30/9/2026 | `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet storage services. A vulnerability in these packages causes transactions created… | |
| Analizada | Alta (7.5) | 0.22% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 26/9/2026 | Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction. | |
| Analizada | Crítica (9.3) | 0.32% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that… | |
| Analizada | Crítica (9.3) | 0.30% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analizada | Crítica (9.3) | 0.30% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analizada | Crítica (9.3) | 0.64% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a… | |
| Analizada | Crítica (9.3) | 0.30% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 26/9/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analizada | Crítica (9.9) | 0.55% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially… | |
| Analizada | Media (6.1) | 0.18% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | |
| Analizada | Alta (8.6) | 0.66% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this… | |
| Pendiente de análisis | Alta (7.1) | 0.30% | — | Canva Mobile APPAI | 21/9/2026 | 21/9/2026 | The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session. | |
| Analizada | Alta (7.4) | 0.10% | — | Qualcomm Cologne FirmwareQualcomm Congo FirmwareQualcomm Cq7790 FirmwareQualcomm Cq7790m Firmware+71 | 17/9/2026 | 22/9/2026 | Transient DOS while parsing frame during channel usage. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Analizada | Alta (7.4) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm C110100 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+148 | 17/9/2026 | 22/9/2026 | Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. | |
| Pendiente de análisis | Crítica (9.3) | 1.6% | — | WNC T-mobile 5G BOX IDUAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an authenticated attacker to execute arbitrary… | |
| Pendiente de análisis | Crítica (9.4) | 2.9% | — | WNC T-mobile 5G BOX IDUAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is directly concatenated into a find command string without proper sanitization. This… | |
| Pendiente de análisis | Alta (8.4) | 0.20% | — | WNC T-mobile 5G BOX IDUAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by… | |
| Pendiente de análisis | Alta (7.1) | 0.37% | — | WNC T-mobile 5G BOX IDUAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web password, WiFi passphrase, and technical… | |
| Pendiente de análisis | Crítica (9.3) | 1.6% | — | WNC T-mobile 5G BOX IDUAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify and sanitize user-supplied input before… | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | WNC T-mobile 5G BOX IDU RouterAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory… | |
| Pendiente de análisis | Alta (8.1) | 0.37% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application… |