Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.4)0.22%—Wpmobile APPAI3/10/20263/10/2026
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaCrítica (9.8)0.49%—Amauri Wpmobile.appAI2/10/20262/10/2026
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate…
AplazadaMedia (6.9)0.24%—Amauri IO Wpmobile APPAI30/9/202630/9/2026
Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83.
Pendiente de análisisAlta (7.1)0.30%—Canva Mobile APPAI21/9/202621/9/2026
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
Pendiente de análisisAlta (8.1)0.37%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
Pendiente de análisisAlta (7.5)0.24%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the…
Pendiente de análisisCrítica (9.8)0.48%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202616/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
Pendiente de análisisAlta (8.2)0.31%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202621/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Application…
Pendiente de análisisAlta (8.2)0.42%—Oracle Mobile Application ServerAI15/9/202621/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
AplazadaAlta (8.6)0.36%—Mobile APP FOR WoocommerceAI27/8/202628/8/2026
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
AplazadaMedia (4.3)0.15%—Shopapper Mobile APP BuilderAI27/8/202628/8/2026
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock…
AnalizadaMedia (6.5)0.35%—Oracle Mobile Application Server18/8/202628/8/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application…
AplazadaCrítica (9.8)0.51%—Menulux Software INC Mobile APPAI3/8/202626/8/2026
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026.
AplazadaMedia (6.9)0.38%—Igloohome Smart Lock Mobile APPAI28/7/202630/7/2026
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
AplazadaAlta (8.7)0.31%—Ghostrobotics Vision 60AIGhostrobotics Vision 60 Mobile APPAI27/7/202627/7/2026
A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can…
AplazadaAlta (8.2)0.34%—Hippoo Mobile APP FOR WoocommerceAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
AplazadaCrítica (9.8)1.6%—Hippoo Mobile APP FOR WoocommerceAI11/6/202617/6/2026
Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.
AplazadaCrítica (9.8)2.9%—Hippoo Mobile APP FOR WoocommerceAI5/6/202617/6/2026
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both…
AplazadaAlta (8.8)0.42%—Kurt Software Studio Writeup Mobile APPAI4/6/202622/7/2026
Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.
AplazadaAlta (8.8)0.43%—Frontier X Mobile ApplicationAISeil X2AI29/5/202622/7/2026
The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations,…
AplazadaMedia (6.3)0.18%—Turkiye Electricity Transmission Corporation Mobile ApplicationAI21/5/202623/7/2026
Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue affects Mobile Application: from 1.6.2 before 1.13.
AplazadaMedia (5.7)0.18%—Turkiye Electricity Transmission Corporation Mobile ApplicationAI21/5/202623/7/2026
Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking. This issue affects Mobile Application: from 1.6.2 before 1.13.
AplazadaBaja (2.9)0.57%—Codewise Tornet Scooter Mobile APPAI3/5/202617/6/2026
A vulnerability has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS/Android. The impacted element is an unknown function of the file /TwoFactor. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be performed from remote. Attacks of this nature are highly…
AplazadaCrítica (9.1)0.50%—Syarif Mobile APP EditorAI19/3/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server.This issue affects Mobile App Editor: from n/a through <= 1.3.1.
AnalizadaMedia (4.8)0.31%—Audiobookshelf Mobile APP26/2/202617/6/2026
Audiobookshelf is a self-hosted audiobook and podcast server. A cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges (or…