Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3069▲ 549 respecto a la semana anterior
Críticas / altas1455▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.32% | — | Wikimedia Wikipedia Android APPAI | 25/9/2026 | 28/9/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: main. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Lenovo Health Android ApplicationAI | 10/9/2026 | 11/9/2026 | A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information. | |
| Aplazada | Alta (8.8) | 0.43% | — | Canva Android APPAI | 4/9/2026 | 8/9/2026 | The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session. | |
| Aplazada | Crítica (9.6) | 0.39% | — | Canva Android APPAI | 4/9/2026 | 8/9/2026 | The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session. | |
| Aplazada | Media (6.9) | 0.39% | — | Mira Android APPAI | 11/8/2026 | 1/9/2026 | When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs,… | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | Datadog Android ApplicationAIGoogle Firebase CrashlyticsAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems. | |
| Pendiente de análisis | Media (6.3) | 0.24% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend. This requires a… | |
| Pendiente de análisis | Media (4.6) | 0.24% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recipient, service, tags, and on-call/incident deep links) and SearchRecentDatabase (the user's full in-app search history).… | |
| Pendiente de análisis | Media (6.4) | 0.29% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process session matches that ID, it unconditionally cancels notification ID 9201 (the Bits AI… | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported with no permission guard. Each accepts a… | |
| Aplazada | Crítica (9.8) | 0.81% | — | Safetipin Android ApplicationAI | 5/8/2026 | 1/10/2026 | My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values. | |
| Aplazada | Alta (8.1) | 0.39% | — | Sirengps Android ApplicationAI | 5/8/2026 | 1/10/2026 | SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is… | |
| Aplazada | Alta (8.7) | 0.44% | — | Line Android APPAI | 4/8/2026 | 28/8/2026 | A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. As a result, an attacker who is able to place crafted content in a profile could cause… | |
| Aplazada | Alta (7.5) | 0.30% | — | Payrange Android APPAI | 9/7/2026 | 9/7/2026 | PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends. | |
| Aplazada | Crítica (9.3) | 0.35% | — | Yarbo Android ApplicationAIYarbo IOS ApplicationAI | 12/6/2026 | 17/6/2026 | The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carrying real-time… | |
| Pendiente de análisis | Media (5.1) | 0.29% | — | Lenovo Android ApplicationAI | 10/6/2026 | 17/6/2026 | A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in browser to overwrite system clipboard contents. | |
| Aplazada | Alta (8.6) | 0.41% | — | Meari IOT SDKAIMeari CloudedgeAIArentiAIMeari Android APPAI | 11/5/2026 | 17/6/2026 | In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys. | |
| Aplazada | Media (6.5) | 0.33% | — | Lotus Cars Android APPAI | 14/8/2025 | 5/7/2026 | The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of service or logic abuse. | |
| Aplazada | Baja (2.4) | 0.19% | — | Smart-tab Android APPAI | 30/9/2024 | 17/6/2026 | Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with physical access to the device may retrieve the credential information and spoof the device to access the related external service. | |
| Aplazada | Baja (3.9) | 0.21% | — | UDN News Android APPAI | 25/6/2024 | 17/6/2026 | udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn. | |
| Aplazada | Baja (3.9) | 0.21% | — | UDN News Android APPAI | 25/6/2024 | 17/6/2026 | udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn. | |
| Aplazada | Alta (8.8) | 0.71% | — | Armorx Android APPAI | 29/4/2024 | 17/6/2026 | ArmorX Android APP's multi-factor authentication (MFA) for the login function is not properly implemented. Remote attackers who obtain user credentials can bypass MFA, allowing them to successfully log into the APP. | |
| Modificada | Crítica (9.8) | 12% | — | Wp2android-turn-wp-site-into-android-app Project Wp2android-turn-wp-site-into-android-app | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com. |