Vulnerabilities

Summary — last 7 days

New vulnerabilities2,771▲ 6 vs. last week
Critical / high1,285▼ 246 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)242▲ 224 vs. last week
–

1,756 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (4.3)0.28%—Mozilla Firefox Mobile9/8/202610/5/2026
A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Firefox for iOS 155.1.
ModifiedCritical (9.8)0.45%—Mozilla Firefox Mobile9/1/20269/3/2026
Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
AnalyzedMedium (4.3)0.26%—Mozilla Firefox Mobile9/1/20269/3/2026
Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.
AnalyzedHigh (8.8)0.35%—Mozilla Firefox Mobile9/1/20269/3/2026
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
AnalyzedMedium (5.4)0.26%—Mozilla Firefox Mobile8/31/20269/3/2026
A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.
DeferredLow (1.9)1.1%—Alexgladkov Claude-in-mobileAI8/27/20268/28/2026
A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the public and may be used for attacks.…
DeferredHigh (8.6)0.36%—Mobile APP FOR WoocommerceAI8/27/20268/28/2026
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
DeferredMedium (4.3)0.15%—Shopapper Mobile APP BuilderAI8/27/20268/28/2026
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock…
DeferredHigh (8.1)0.33%—Classified Listing Mobile Number VerificationAI8/26/20268/26/2026
The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.6.0. This is due to missing server-side Firebase OTP validation in the process_otp_login() function. This makes it possible for unauthenticated attackers to…
AnalyzedMedium (6.5)0.35%—Oracle Mobile Application Server8/18/20268/28/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application…
AnalyzedMedium (6.5)0.27%—Mozilla Firefox Mobile8/18/20268/25/2026
Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
AnalyzedMedium (5.4)0.25%—Mozilla Firefox Mobile8/18/20268/25/2026
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
AnalyzedMedium (6.5)0.27%—Mozilla Firefox Mobile8/18/20268/19/2026
Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
DeferredHigh (7.5)0.39%—Wpmobile APPAI8/13/20268/14/2026
Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.
Awaiting AnalysisMedium (5.4)0.23%—HCL Bigfix MobileAI8/10/20268/28/2026
HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input.
Awaiting AnalysisMedium (4.3)0.29%—HCL Bigfix MobileAI8/10/20268/28/2026
HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting.
AnalyzedHigh (7.6)0.15%—Qualcomm Sm6225p FirmwareQualcomm Sm6450p FirmwareQualcomm Sm6475p FirmwareQualcomm Sm6475q Firmware+2078/4/20268/6/2026
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
AnalyzedCritical (9.6)0.19%—Qualcomm Sm7550p FirmwareQualcomm Sm7635p FirmwareQualcomm Sm7675 FirmwareQualcomm Sm7675p Firmware+1978/4/20268/6/2026
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
AnalyzedHigh (7.4)0.16%—Qualcomm Orne FirmwareQualcomm Palawan25 FirmwareQualcomm Pandeiro FirmwareQualcomm Qln1083bd Firmware+508/4/20268/6/2026
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
AnalyzedHigh (7.5)0.25%—Qualcomm Sdx57m FirmwareQualcomm Sdx61 FirmwareQualcomm Sdx71m FirmwareQualcomm Sm6650p Firmware+1248/4/20268/6/2026
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
AnalyzedHigh (8.1)0.21%—Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1398/4/20268/6/2026
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
AnalyzedMedium (6.5)0.17%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1438/4/20268/6/2026
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
AnalyzedMedium (6.5)0.17%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1408/4/20268/6/2026
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
DeferredCritical (9.8)0.51%—Menulux Software INC Mobile APPAI8/3/20268/26/2026
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026.
DeferredMedium (6.5)0.27%—Authora Easy Login With Mobile NumberAI8/1/20268/26/2026
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know…