Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.37% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application… | |
| Pendiente de análisis | Alta (7.5) | 0.24% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application… | |
| Pendiente de análisis | Alta (8.2) | 0.31% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Application… | |
| Pendiente de análisis | Alta (8.2) | 0.42% | — | Oracle Mobile Application ServerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Mobile Application Server | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application… | |
| Aplazada | Alta (8.8) | 0.43% | — | Frontier X Mobile ApplicationAISeil X2AI | 29/5/2026 | 22/7/2026 | The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations,… | |
| Aplazada | Media (6.3) | 0.18% | — | Turkiye Electricity Transmission Corporation Mobile ApplicationAI | 21/5/2026 | 23/7/2026 | Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue affects Mobile Application: from 1.6.2 before 1.13. | |
| Aplazada | Media (5.7) | 0.18% | — | Turkiye Electricity Transmission Corporation Mobile ApplicationAI | 21/5/2026 | 23/7/2026 | Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking. This issue affects Mobile Application: from 1.6.2 before 1.13. | |
| Aplazada | Media (4.7) | 0.18% | — | Yosmart Yolink HUBAIYosmart Yolink Mobile ApplicationAIYosmart Yolink Mqtt BrokerAI | 6/10/2025 | 17/6/2026 | Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. This affects YoLink Hub 0382, YoLink… | |
| Aplazada | Crítica (9.8) | 2.1% | — | Gardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI | 25/7/2025 | 17/6/2026 | Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an attacker to execute… | |
| Aplazada | Crítica (9.1) | 0.49% | — | Gardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI | 25/7/2025 | 17/6/2026 | Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits. | |
| Aplazada | Crítica (9.4) | 0.28% | 💥 PoC | Gardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI | 25/7/2025 | 17/6/2026 | A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack.… | |
| Aplazada | Crítica (10) | 0.32% | — | Ataturk University Ata-aof Mobile ApplicationAI | 24/6/2025 | 17/6/2026 | Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass. This issue affects ATA-AOF Mobile Application: before 20.06.2025. | |
| Aplazada | Media (6.2) | 0.17% | — | HP Advance Mobile ApplicationsAIApple IOSAIGoogle AndroidAI | 12/6/2024 | 17/6/2026 | HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. | |
| Analizada | Media (5.5) | 0.61% | — | Microsoft Intune Mobile Application Management | 14/5/2024 | 17/6/2026 | Microsoft Intune for Android Mobile Application Management Tampering Vulnerability | |
| Modificada | Alta (7.2) | 0.44% | — | Amodat Mobile Application Gateway | 13/6/2022 | 17/6/2026 | attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel. | |
| Modificada | Crítica (9.8) | 0.45% | — | Amodat Mobile Application Gateway | 13/6/2022 | 17/6/2026 | The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'-- | |
| Modificada | Media (6.1) | 1.0% | — | Keycloak Gatekeeper Project Keycloak GatekeeperRedhat Mobile Application Platform | 28/1/2021 | 17/6/2026 | A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0 | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Media (6.1) | 0.93% | — | Redhat Mobile Application Platform | 29/9/2017 | 17/6/2026 | It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored XSS attack on an application administrator using App Studio. | |
| Modificada | Media (6.3) | 0.70% | — | Redhat Mobile Application Platform | 29/9/2017 | 17/6/2026 | The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints. | |
| Modificada | Crítica (9.8) | 1.4% | — | Redhat Mobile Application Platform | 29/9/2017 | 17/6/2026 | A flaw was discovered in the file editor of millicore, affecting versions before 3.19.0 and 4.x before 4.5.0, which allows files to be executed as well as created. An attacker could use this flaw to compromise other users or teams projects stored in source control management of the RHMAP Core installation. | |
| Modificada | Media (6.5) | 0.89% | — | Redhat Feedhenry Enterprise Mobile Application Platform | 20/9/2017 | 17/6/2026 | Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform. |