Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.40% | — | Opensecurity Mobile Security Framework | 26/3/2026 | 17/6/2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `mobsf/MobSF/utils.py` (lines 542-566) uses Python string formatting (`%`) to construct SQL queries with table names read from a SQLite database's `sqlite_master` table. When a security analyst uses… | |
| Analizada | Media (4.8) | 0.35% | — | Opensecurity Mobile Security Framework | 27/1/2026 | 17/6/2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session by uploading a malicious APK. The `android:host`… | |
| Analizada | Media (6.5) | 0.60% | — | Opensecurity Mobile Security Framework | 2/9/2025 | 17/6/2026 | MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF process. This issue has been patched in version 4.4.1. | |
| Analizada | Baja (1.3) | 0.78% | — | Opensecurity Mobile Security Framework | 2/9/2025 | 17/6/2026 | MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.commonprefix, which allows an authenticated user to download files outside the DWD_DIR download directory from "neighboring" directories whose absolute paths begin with the… | |
| Analizada | Media (6.5) | 0.50% | — | Opensecurity Mobile Security Framework | 5/5/2025 | 17/6/2026 | MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to internal security teams, audit teams, and external vendors. MobSF… | |
| Analizada | Alta (8.6) | 0.32% | — | Opensecurity Mobile Security Framework | 5/5/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions up to and including 4.3.2. The vulnerability arises from improper sanitization of user-supplied SVG files… | |
| Analizada | Crítica (9.8) | 0.47% | — | Opensecurity Mobile Security Framework | 31/3/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to SSRF abuse using DNS rebinding technique. This vulnerability is… | |
| Analizada | Alta (8.5) | 0.36% | — | Opensecurity Mobile Security Framework | 5/2/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepted. This issue has… | |
| Analizada | Media (4.8) | 0.46% | — | Opensecurity Mobile Security Framework | 5/2/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), and periods (.).… | |
| Analizada | Alta (8.4) | 0.39% | — | Opensecurity Mobile Security Framework | 5/2/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), and periods (.).… | |
| Analizada | Alta (7.5) | 0.41% | — | Opensecurity Mobile Security Framework | 3/12/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the _check_url method is specified as allow_redirects=True, which allows a server-side request forgery when… | |
| Analizada | Media (5.4) | 0.52% | — | Opensecurity Mobile Security Framework | 3/12/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the filename parameter. As a result, a malicious user can upload a script file to the system. When users… | |
| Analizada | Crítica (9.8) | 0.96% | — | Opensecurity Mobile Security Framework | 19/8/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension files, the measure intended to prevent… | |
| Analizada | Media (5.4) | 1.0% | — | Opensecurity Mobile Security Framework | 31/7/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5. | |
| Aplazada | Baja (3.5) | 0.23% | — | Bitdefender Mobile SecurityAI | 3/6/2024 | 17/6/2026 | Incorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows attackers to bypass fingerprint authentication due to the use of a deprecated API. | |
| Analizada | Media (4.3) | 0.51% | — | Opensecurity Mobile Security Framework | 4/4/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organization’s infrastructure. When a… | |
| Analizada | Alta (7.5) | 0.72% | — | Opensecurity Mobile Security Framework | 22/3/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In version 3.9.5 Beta and prior, MobSF does not perform any input validation when extracting the hostnames in `android:host`, so requests can also be sent to local… | |
| Modificada | Media (6.1) | 1.6% | — | Trendmicro Mobile Security | 23/1/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to, but not identical to, CVE-2023-41176. | |
| Modificada | Media (6.1) | 0.46% | — | Trendmicro Mobile Security | 23/1/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to, but not identical to, CVE-2023-41178. | |
| Modificada | Media (6.1) | 1.6% | — | Trendmicro Mobile Security | 23/1/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to, but not identical to, CVE-2023-41177. | |
| Modificada | Alta (7.5) | 0.86% | — | Opensecurity Mobile Security Framework | 21/9/2023 | 17/6/2026 | Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy… | |
| Modificada | Alta (7.5) | 1.5% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may contain sensitive information regarding the product. | |
| Modificada | Alta (8.8) | 3.0% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Alta (8.8) | 2.9% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Media (6.5) | 2.0% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.… |