Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.9)0.21%—Lobbyuniverse Lobby28/7/202517/6/2026
A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.maverick.lobby. The manipulation leads to improper export of android application components. The attack…
AplazadaAlta (7.1)0.25%—Wphobby BackwpAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphobby Backwp backwp allows Reflected XSS.This issue affects Backwp: from n/a through <= 2.0.2.
AplazadaAlta (7.4)0.19%—Wphobby BackwpAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wphobby Backwp backwp allows Path Traversal.This issue affects Backwp: from n/a through <= 2.0.2.
AnalizadaMedia (6.1)0.62%—Wphobby Post Sync26/2/202517/6/2026
The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AnalizadaMedia (4.8)0.19%—Robbychen Simple Buttons Creator15/4/202417/6/2026
The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
AnalizadaMedia (6.1)0.24%—Robbychen Simple Buttons Creator15/4/202417/6/2026
The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored…
ModificadaCrítica (9.8)0.67%—Innosa Probbys Project Innosa Probbys15/9/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Innosa Probbys allows SQL Injection. This issue affects Probbys: before 2.
ModificadaAlta (7.5)1.4%—Gobby Project Gobby26/12/202017/6/2026
Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls.
ModificadaAlta (7.8)0.33%—Hidglobal Easylobby Solo21/3/201917/6/2026
EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.
ModificadaAlta (7.8)0.34%—Hidglobal Easylobby Solo21/3/201917/6/2026
EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this vulnerability to perform unauthorized actions on the computer.
ModificadaAlta (7.1)0.29%—Hidglobal Easylobby Solo21/3/201917/6/2026
EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or launch new processes at will.
ModificadaMedia (5.5)0.21%—Hidglobal Easylobby Solo21/3/201917/6/2026
EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attacker could exploit this vulnerability to view stored social security numbers.
ModificadaAlta (7.8)0.36%—Jollytech Lobby Track21/3/201917/6/2026
Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and accessing the print badge screen, an attacker could exploit this vulnerability using the command line to break out of kiosk mode.
ModificadaAlta (7.8)0.36%—Jollytech Lobby Track21/3/201917/6/2026
Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and signing in as a visitor, an attacker could exploit this vulnerability using the command line to break out of kiosk mode.
ModificadaMedia (5.5)0.32%—Jollytech Lobby Track21/3/201917/6/2026
Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor function while in kiosk mode. By visiting the kiosk and selecting find visitor, an attacker could exploit this vulnerability to delete visitor records or remove a host.
ModificadaAlta (7.8)0.38%—Jollytech Lobby Track21/3/201917/6/2026
Lobby Track Desktop contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.
ModificadaAlta (7.1)0.31%—Jollytech Lobby Track21/3/201917/6/2026
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk mode. By using attack vectors outlined in kiosk breakout, an attacker could exploit this vulnerability to view and edit the database.
ModificadaMedia (5.5)0.30%—Jollytech Lobby Track21/3/201917/6/2026
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and viewing the driver's license column, an attacker could exploit this vulnerability to view the driver's license number and other personal information.
ModificadaMedia (5.5)0.35%—Jollytech Lobby Track21/3/201917/6/2026
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and clicking on reports, an attacker could exploit this vulnerability to gain access to all visitor records and obtain sensitive information.
ModificadaMedia (5.4)0.29%—Innopage Giga Hobby21/10/201417/6/2026
The GIGA HOBBY (aka com.innopage.store.gigahobby) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Longluntan Gzonerc - THE RC Hobby HUB21/10/201417/6/2026
The GzoneRC - The RC Hobby Hub (aka com.wGzoneRC) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Hobbylobby Hobby Lobby Stores9/9/201417/6/2026
The Hobby Lobby Stores (aka com.hobbylobbystores.android) application 2.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.8)0.81%—Ubuntu Developers Obby10/2/201416/6/2026
obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate.