Vulnerabilities
Summary — last 7 days
New vulnerabilities2,759▲ 5 vs. last week
Critical / high1,275▼ 253 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)242▲ 224 vs. last week
1,756 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.2) | — | — | Hayat Health Facilities INC Hayat MobileAI | 10/9/2026 | 10/9/2026 | Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass. This issue affects Hayat Mobile: from 3.3.0 before 3.4.0. | |
| Analyzed | High (7.8) | 0.11% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+214 | 10/6/2026 | 10/9/2026 | Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations. | |
| Analyzed | High (7.5) | 0.26% | — | Qualcomm Congo FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Orne FirmwareQualcomm Pandeiro Firmware+10 | 10/6/2026 | 10/9/2026 | Transient DOS when processing a continuous receive command with a zero-sized global configuration override. | |
| Analyzed | High (7.8) | 0.12% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm Ar8031 FirmwareQualcomm Cologne FirmwareQualcomm Congo Firmware+213 | 10/6/2026 | 10/9/2026 | Memory corruption when processing draw objects of incorrect type during graphics command list execution. | |
| Analyzed | High (7.8) | 0.11% | — | Qualcomm Congo FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+68 | 10/6/2026 | 10/9/2026 | Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization. | |
| Analyzed | High (7.1) | 0.09% | — | Qualcomm Xrv9209 FirmwareQualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne Firmware+288 | 10/6/2026 | 10/9/2026 | Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed. | |
| Analyzed | High (7.8) | 0.11% | — | Qualcomm Sar1165p FirmwareQualcomm Sc8380xp FirmwareQualcomm Snapdragon 662 Mobile Platform FirmwareQualcomm Sm4875 Firmware+109 | 10/6/2026 | 10/9/2026 | Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms. | |
| Analyzed | Medium (6.7) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Congo FirmwareQualcomm Fastconnect 6200 Firmware+41 | 10/6/2026 | 10/9/2026 | Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization. | |
| Analyzed | Medium (6.7) | 0.11% | — | Qualcomm Congo FirmwareQualcomm Cq8845s FirmwareQualcomm Cq8850ns FirmwareQualcomm Fastconnect 6200 Firmware+47 | 10/6/2026 | 10/9/2026 | Memory Corruption when processing camera operations due to out-of-bounds write during driver updates. | |
| Analyzed | Medium (6.7) | 0.11% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm Cologne FirmwareQualcomm Cq2390m FirmwareQualcomm Cq2390s Firmware+151 | 10/6/2026 | 10/9/2026 | Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation. | |
| Analyzed | Medium (6.7) | 0.11% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm Cologne FirmwareQualcomm Congo FirmwareQualcomm Cq2390m Firmware+199 | 10/6/2026 | 10/9/2026 | Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver. | |
| Analyzed | Medium (6.7) | 0.11% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm Cologne FirmwareQualcomm Cq2390m FirmwareQualcomm Cq2390s Firmware+152 | 10/6/2026 | 10/9/2026 | Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size. | |
| Analyzed | High (7.8) | 0.10% | — | Qualcomm Qca6698au FirmwareQualcomm Qca6797aq FirmwareQualcomm Qcc710 FirmwareQualcomm Qcm2290 Firmware+162 | 10/6/2026 | 10/9/2026 | Memory corruption when non-secure loader rewrites page tables before secure memory initialization. | |
| Analyzed | Medium (6.6) | 0.09% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9205s Modem Firmware+162 | 10/6/2026 | 10/9/2026 | Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters. | |
| Deferred | Medium (5.4) | 0.22% | — | Wpmobile APPAI | 10/3/2026 | 10/6/2026 | The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Deferred | Critical (9.8) | 0.49% | 💥 PoC | Amauri Wpmobile.appAI | 10/2/2026 | 10/2/2026 | The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate… | |
| Deferred | Medium (6.9) | 0.24% | — | Amauri IO Wpmobile APPAI | 9/30/2026 | 9/30/2026 | Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83. | |
| Deferred | High (7.1) | 0.09% | — | Freshlightlab WP Mobile MenuAI | 9/30/2026 | 9/30/2026 | The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every… | |
| Deferred | High (7.5) | 0.24% | — | Parla Auto Automotive Trading Limited Company Detawix Mobile WEB PortalAI | 9/29/2026 | 9/30/2026 | Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19. | |
| Analyzed | Medium (5.4) | 0.15% | — | Mozilla Firefox Mobile | 9/29/2026 | 10/5/2026 | Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157. | |
| Deferred | High (8.7) | 0.30% | — | BSV Wallet ToolboxAIBSV Wallet Toolbox ClientAIBSV Wallet Toolbox MobileAI | 9/24/2026 | 9/30/2026 | `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet storage services. A vulnerability in these packages causes transactions created… | |
| Analyzed | High (7.5) | 0.22% | — | Adobe ConnectAdobe Connect FOR Mobile | 9/22/2026 | 9/26/2026 | Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction. | |
| Analyzed | Critical (9.3) | 0.32% | — | Adobe ConnectAdobe Connect FOR Mobile | 9/22/2026 | 9/25/2026 | Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that… | |
| Analyzed | Critical (9.3) | 0.30% | — | Adobe ConnectAdobe Connect FOR Mobile | 9/22/2026 | 9/25/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analyzed | Critical (9.3) | 0.30% | — | Adobe ConnectAdobe Connect FOR Mobile | 9/22/2026 | 9/25/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… |