Vulnerabilities
Summary — last 7 days
New vulnerabilities2,771▲ 6 vs. last week
Critical / high1,285▼ 246 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)242▲ 224 vs. last week
1,756 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (4.3) | 0.28% | — | Mozilla Firefox Mobile | 9/8/2026 | 10/5/2026 | A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Firefox for iOS 155.1. | |
| Modified | Critical (9.8) | 0.45% | — | Mozilla Firefox Mobile | 9/1/2026 | 9/3/2026 | Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. | |
| Analyzed | Medium (4.3) | 0.26% | — | Mozilla Firefox Mobile | 9/1/2026 | 9/3/2026 | Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155. | |
| Analyzed | High (8.8) | 0.35% | — | Mozilla Firefox Mobile | 9/1/2026 | 9/3/2026 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. | |
| Analyzed | Medium (5.4) | 0.26% | — | Mozilla Firefox Mobile | 8/31/2026 | 9/3/2026 | A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0. | |
| Deferred | Low (1.9) | 1.1% | — | Alexgladkov Claude-in-mobileAI | 8/27/2026 | 8/28/2026 | A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the public and may be used for attacks.… | |
| Deferred | High (8.6) | 0.36% | — | Mobile APP FOR WoocommerceAI | 8/27/2026 | 8/28/2026 | Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. | |
| Deferred | Medium (4.3) | 0.15% | — | Shopapper Mobile APP BuilderAI | 8/27/2026 | 8/28/2026 | The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock… | |
| Deferred | High (8.1) | 0.33% | — | Classified Listing Mobile Number VerificationAI | 8/26/2026 | 8/26/2026 | The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.6.0. This is due to missing server-side Firebase OTP validation in the process_otp_login() function. This makes it possible for unauthenticated attackers to… | |
| Analyzed | Medium (6.5) | 0.35% | — | Oracle Mobile Application Server | 8/18/2026 | 8/28/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application… | |
| Analyzed | Medium (6.5) | 0.27% | — | Mozilla Firefox Mobile | 8/18/2026 | 8/25/2026 | Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | |
| Analyzed | Medium (5.4) | 0.25% | — | Mozilla Firefox Mobile | 8/18/2026 | 8/25/2026 | Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | |
| Analyzed | Medium (6.5) | 0.27% | — | Mozilla Firefox Mobile | 8/18/2026 | 8/19/2026 | Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154. | |
| Deferred | High (7.5) | 0.39% | — | Wpmobile APPAI | 8/13/2026 | 8/14/2026 | Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions. | |
| Awaiting Analysis | Medium (5.4) | 0.23% | — | HCL Bigfix MobileAI | 8/10/2026 | 8/28/2026 | HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input. | |
| Awaiting Analysis | Medium (4.3) | 0.29% | — | HCL Bigfix MobileAI | 8/10/2026 | 8/28/2026 | HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting. | |
| Analyzed | High (7.6) | 0.15% | — | Qualcomm Sm6225p FirmwareQualcomm Sm6450p FirmwareQualcomm Sm6475p FirmwareQualcomm Sm6475q Firmware+207 | 8/4/2026 | 8/6/2026 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | |
| Analyzed | Critical (9.6) | 0.19% | — | Qualcomm Sm7550p FirmwareQualcomm Sm7635p FirmwareQualcomm Sm7675 FirmwareQualcomm Sm7675p Firmware+197 | 8/4/2026 | 8/6/2026 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. | |
| Analyzed | High (7.4) | 0.16% | — | Qualcomm Orne FirmwareQualcomm Palawan25 FirmwareQualcomm Pandeiro FirmwareQualcomm Qln1083bd Firmware+50 | 8/4/2026 | 8/6/2026 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | |
| Analyzed | High (7.5) | 0.25% | — | Qualcomm Sdx57m FirmwareQualcomm Sdx61 FirmwareQualcomm Sdx71m FirmwareQualcomm Sm6650p Firmware+124 | 8/4/2026 | 8/6/2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | |
| Analyzed | High (8.1) | 0.21% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+139 | 8/4/2026 | 8/6/2026 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | |
| Analyzed | Medium (6.5) | 0.17% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+143 | 8/4/2026 | 8/6/2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | |
| Analyzed | Medium (6.5) | 0.17% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+140 | 8/4/2026 | 8/6/2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | |
| Deferred | Critical (9.8) | 0.51% | — | Menulux Software INC Mobile APPAI | 8/3/2026 | 8/26/2026 | Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026. | |
| Deferred | Medium (6.5) | 0.27% | — | Authora Easy Login With Mobile NumberAI | 8/1/2026 | 8/26/2026 | The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know… |