Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.46%—Find-my-wayAI28/7/202630/7/2026
find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The lookup() function passes req.method into find(), and find()…
Pendiente de análisisMedia (5.3)0.40%—Apple Find MYAI21/7/202623/7/2026
The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may result in unauthorized removal of…
AplazadaMedia (5.3)0.68%—Find-my-wayAI18/9/202417/6/2026
find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is generated any time one has two parameters within a single segment, when adding a `-` at the end, like `/:a-:b-`. This…
ModificadaMedia (6.8)0.32%—Samsung Find MY Mobile5/12/202317/6/2026
Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotely by resetting the Samsung Account password with SMS verification when user lost the device.
ModificadaBaja (3.3)0.23%—Samsung Find MY Mobile9/9/202217/6/2026
Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log.
ModificadaMedia (5.3)0.82%—Samsung Find MY Mobile12/7/202217/6/2026
Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.
ModificadaBaja (3.3)0.20%—Samsung Find MY Mobile7/6/202217/6/2026
Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log.
ModificadaBaja (3.3)0.20%—Samsung Find MY Mobile7/6/202217/6/2026
Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permission to get sim card information through device log.
ModificadaMedia (5.3)1.3%—Find MY Blocks Project Find MY Blocks18/10/202117/6/2026
The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enumerate private posts' titles.
ModificadaAlta (7.5)1.7%—Find-my-way Project Find-my-way8/11/202017/6/2026
This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by default, and if versioned routes are not being used, this could lead to a denial of service. Accept-Version can be used as an unkeyed header in a cache poisoning attack.