Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)0.20%—Kruger Matz SmartphoneAISpsoftmobile ApplockAI30/5/202517/6/2026
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any other malicious application, with no granted Android system permissions, to inject an…
ModificadaCrítica (9.1)0.38%—Devicefarmer Smartphone Test Farm29/1/202417/6/2026
DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.
ModificadaMedia (4.3)0.24%—Motorola Smartphone Firmware1/9/202317/6/2026
I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user from dialing emergency services. This…
ModificadaCrítica (9.8)1.4%—Mobileiron SentryMobileiron Virtual Smartphone Platform13/2/202017/6/2026
MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
ModificadaAlta (7.5)1.5%—ATT Mobileiron SentryATT Mobileiron Virtual Smartphone Platform12/2/202017/6/2026
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
ModificadaCrítica (9.1)4.0%—Mobileiron Virtual Smartphone PlatformMobileiron Sentry8/1/202017/6/2026
MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords
ModificadaCrítica (9.8)9.3%—Bulbsecurity Smartphone Pentest Framework3/1/202016/6/2026
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.
ModificadaAlta (8.8)1.7%—Bulbsecurity Smartphone Pentest Framework3/1/202016/6/2026
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2) guessPassword.pl in frameworkgui/; the filename parameter to (3) CSAttack.pl or (4) SEAttack.pl in frameworkgui/; the…
ModificadaAlta (7.8)0.89%—Huawei P8 Smartphone Firmware2/8/201617/6/2026
Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6192.
ModificadaAlta (7.3)0.84%—Huawei P8 Smartphone Firmware2/8/201617/6/2026
Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6193.
ModificadaBaja (1.8)0.40%—Okb.co.jp Smartphone Passbook15/2/201517/6/2026
The Ogaki Kyoritsu Bank Smartphone Passbook application 1.0.0 for Android creates a log file containing input data from the user, which allows attackers to obtain sensitive information by reading a file.
ModificadaMedia (4.6)0.42%—Bulbsecurity Smartphone Pentest Framework20/10/201416/6/2026
The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions (777) for all files in the frameworkgui/ directory, which allows local users to obtain sensitive information or inject arbitrary Perl code via direct access to these files.
ModificadaMedia (5)1.3%—Bulbsecurity Smartphone Pentest Framework20/10/201416/6/2026
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote attackers to obtain the plaintext database password via a direct request.
ModificadaMedia (6.8)0.67%—Bulbsecurity Smartphone Pentest Framework20/10/201416/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allow remote attackers to hijack the authentication of administrators for requests that conduct (1) shell metacharacter or (2) SQL injection attacks or (3) send an SMS message.
ModificadaMedia (6.8)1.3%—Bulbsecurity Smartphone Pentest Framework20/10/201416/6/2026
Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute arbitrary SQL commands via the (1) agentPhNo, (2) controlPhNo, (3) agentURLPath, (4) agentControlKey, or (5) platformDD1 parameter to frameworkgui/attach2Agents.pl; the (6)…
ModificadaBaja (3.3)0.73%—Softbank Wi-fi Spot Configuration SoftwareSoftbank Mobile Wi-fi RouterSoftbank NEC 3G HandsetSoftbank Panasonic 3G Handset+917/6/201316/6/2026
SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi application before 1.7.1, SoftBank Windows Mobile smartphones with the…