Vulnerabilities
Summary — last 7 days
New vulnerabilities2,544▼ 345 vs. last week
Critical / high1,339▲ 68 vs. last week
New active exploitation (KEV)6▼ 6 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
13 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Low (1.9) | 0.21% | — | Lobbyuniverse Lobby | 7/28/2025 | 6/17/2026 | A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.maverick.lobby. The manipulation leads to improper export of android application components. The attack… | |
| Modified | High (7.8) | 0.33% | — | Hidglobal Easylobby Solo | 3/21/2019 | 6/17/2026 | EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application. | |
| Modified | High (7.8) | 0.34% | — | Hidglobal Easylobby Solo | 3/21/2019 | 6/17/2026 | EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this vulnerability to perform unauthorized actions on the computer. | |
| Modified | High (7.1) | 0.29% | — | Hidglobal Easylobby Solo | 3/21/2019 | 6/17/2026 | EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or launch new processes at will. | |
| Modified | Medium (5.5) | 0.21% | — | Hidglobal Easylobby Solo | 3/21/2019 | 6/17/2026 | EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attacker could exploit this vulnerability to view stored social security numbers. | |
| Modified | High (7.8) | 0.36% | — | Jollytech Lobby Track | 3/21/2019 | 6/17/2026 | Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and accessing the print badge screen, an attacker could exploit this vulnerability using the command line to break out of kiosk mode. | |
| Modified | High (7.8) | 0.36% | — | Jollytech Lobby Track | 3/21/2019 | 6/17/2026 | Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and signing in as a visitor, an attacker could exploit this vulnerability using the command line to break out of kiosk mode. | |
| Modified | Medium (5.5) | 0.32% | — | Jollytech Lobby Track | 3/21/2019 | 6/17/2026 | Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor function while in kiosk mode. By visiting the kiosk and selecting find visitor, an attacker could exploit this vulnerability to delete visitor records or remove a host. | |
| Modified | High (7.8) | 0.38% | — | Jollytech Lobby Track | 3/21/2019 | 6/17/2026 | Lobby Track Desktop contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application. | |
| Modified | High (7.1) | 0.31% | — | Jollytech Lobby Track | 3/21/2019 | 6/17/2026 | Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk mode. By using attack vectors outlined in kiosk breakout, an attacker could exploit this vulnerability to view and edit the database. | |
| Modified | Medium (5.5) | 0.30% | — | Jollytech Lobby Track | 3/21/2019 | 6/17/2026 | Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and viewing the driver's license column, an attacker could exploit this vulnerability to view the driver's license number and other personal information. | |
| Modified | Medium (5.5) | 0.35% | — | Jollytech Lobby Track | 3/21/2019 | 6/17/2026 | Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and clicking on reports, an attacker could exploit this vulnerability to gain access to all visitor records and obtain sensitive information. | |
| Modified | Medium (5.4) | 0.27% | — | Hobbylobby Hobby Lobby Stores | 9/9/2014 | 6/17/2026 | The Hobby Lobby Stores (aka com.hobbylobbystores.android) application 2.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |