Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI | 11/9/2026 | 11/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users… | |
| Aplazada | Media (4.3) | 0.15% | — | Shopapper Mobile APP BuilderAI | 27/8/2026 | 28/8/2026 | The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock… | |
| Aplazada | Media (6.5) | 0.48% | — | Appcheap APP BuilderAI | 29/7/2026 | 30/7/2026 | A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization Collision combined with symlink following behavior. APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app… | |
| Aplazada | Media (5.3) | 0.51% | — | Appcheap APP BuilderAI | 2/5/2026 | 17/6/2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 5.6.0. This is due to missing authorization validation in the `upload_avatar()` function, which accepts an attacker-controlled `user_id` parameter… | |
| Aplazada | Media (6.5) | 0.28% | — | Appcheap APP BuilderAI | 21/3/2026 | 17/6/2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.10. This is due to the `verify_role()` function in `AuthTrails.php` explicitly whitelisting the `wcfm_vendor` role alongside `subscriber` and `customer`,… | |
| Aplazada | Alta (7.5) | 0.25% | — | Knowband Mobile APP BuilderAI | 31/12/2025 | 17/6/2026 | The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users. | |
| Aplazada | Media (5.3) | 0.31% | — | Appcheap APP BuilderAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in App Cheap App Builder app-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects App Builder: from n/a through <= 5.5.6. | |
| Modificada | Alta (7.5) | 0.45% | — | Stacksmarket Stacks Mobile APP Builder | 4/11/2024 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. | |
| Modificada | Crítica (9.8) | 0.51% | — | Stacksmarket Stacks Mobile APP Builder | 4/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. | |
| Modificada | Crítica (9.8) | 8.1% | — | Stacksmarket Stacks Mobile APP Builder | 28/10/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. | |
| Analizada | Crítica (9.8) | 0.61% | — | Appcheap APP Builder | 25/10/2024 | 17/6/2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password() and update_password() functions not having enough controls to prevent a… | |
| Modificada | Alta (7.5) | 0.45% | — | Appcheap APP Builder | 21/8/2024 | 17/6/2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Injection via the ‘app-builder-search’ parameter in all versions up to, and including, 4.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Media (6.5) | 0.31% | — | Appcheap APP BuilderAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Appcheap.Io App Builder allows Stored XSS.This issue affects App Builder: from n/a through 3.8.8. | |
| Modificada | Media (6.1) | 0.33% | — | Appcheap APP Builder | 10/4/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Builder: from n/a through 3.8.7. | |
| Aplazada | Media (4.8) | 0.37% | — | Esri Portal FOR Arcgis Enterprise WEB APP BuilderAI | 4/4/2024 | 17/6/2026 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link that is stored in a web map link which when clicked could potentially execute arbitrary JavaScript code in the… | |
| Modificada | Crítica (9.8) | 13% | — | Webapp-builder Project Webapp-builder | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/ | |
| Modificada | Crítica (9.8) | 11% | — | Mobile-app-builder-by-wappress Project Mobile-app-builder-by-wappress | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com. | |
| Modificada | Crítica (9.8) | 27% | — | Mobile-friendly-app-builder-by-easytouch Project Mobile-friendly-app-builder-by-easytouch | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content. | |
| Modificada | Media (5.4) | 0.27% | — | Topappsbuilder Project Animal Kaiser Zangetsu | 20/9/2014 | 17/6/2026 | The Animal Kaiser Zangetsu (aka com.wAnimalKaiserZangetsu) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |