Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.9) | 0.21% | — | Lobbyuniverse Lobby | 28/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.maverick.lobby. The manipulation leads to improper export of android application components. The attack… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wphobby BackwpAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphobby Backwp backwp allows Reflected XSS.This issue affects Backwp: from n/a through <= 2.0.2. | |
| Aplazada | Alta (7.4) | 0.19% | — | Wphobby BackwpAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wphobby Backwp backwp allows Path Traversal.This issue affects Backwp: from n/a through <= 2.0.2. | |
| Analizada | Media (6.1) | 0.62% | — | Wphobby Post Sync | 26/2/2025 | 17/6/2026 | The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (4.8) | 0.19% | — | Robbychen Simple Buttons Creator | 15/4/2024 | 17/6/2026 | The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | |
| Analizada | Media (6.1) | 0.24% | — | Robbychen Simple Buttons Creator | 15/4/2024 | 17/6/2026 | The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored… | |
| Modificada | Crítica (9.8) | 0.67% | — | Innosa Probbys Project Innosa Probbys | 15/9/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Innosa Probbys allows SQL Injection. This issue affects Probbys: before 2. | |
| Modificada | Alta (7.5) | 1.4% | — | Gobby Project Gobby | 26/12/2020 | 17/6/2026 | Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls. | |
| Modificada | Alta (7.8) | 0.33% | — | Hidglobal Easylobby Solo | 21/3/2019 | 17/6/2026 | EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application. | |
| Modificada | Alta (7.8) | 0.34% | — | Hidglobal Easylobby Solo | 21/3/2019 | 17/6/2026 | EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this vulnerability to perform unauthorized actions on the computer. | |
| Modificada | Alta (7.1) | 0.29% | — | Hidglobal Easylobby Solo | 21/3/2019 | 17/6/2026 | EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or launch new processes at will. | |
| Modificada | Media (5.5) | 0.21% | — | Hidglobal Easylobby Solo | 21/3/2019 | 17/6/2026 | EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attacker could exploit this vulnerability to view stored social security numbers. | |
| Modificada | Alta (7.8) | 0.36% | — | Jollytech Lobby Track | 21/3/2019 | 17/6/2026 | Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and accessing the print badge screen, an attacker could exploit this vulnerability using the command line to break out of kiosk mode. | |
| Modificada | Alta (7.8) | 0.36% | — | Jollytech Lobby Track | 21/3/2019 | 17/6/2026 | Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and signing in as a visitor, an attacker could exploit this vulnerability using the command line to break out of kiosk mode. | |
| Modificada | Media (5.5) | 0.32% | — | Jollytech Lobby Track | 21/3/2019 | 17/6/2026 | Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor function while in kiosk mode. By visiting the kiosk and selecting find visitor, an attacker could exploit this vulnerability to delete visitor records or remove a host. | |
| Modificada | Alta (7.8) | 0.38% | — | Jollytech Lobby Track | 21/3/2019 | 17/6/2026 | Lobby Track Desktop contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application. | |
| Modificada | Alta (7.1) | 0.31% | — | Jollytech Lobby Track | 21/3/2019 | 17/6/2026 | Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk mode. By using attack vectors outlined in kiosk breakout, an attacker could exploit this vulnerability to view and edit the database. | |
| Modificada | Media (5.5) | 0.30% | — | Jollytech Lobby Track | 21/3/2019 | 17/6/2026 | Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and viewing the driver's license column, an attacker could exploit this vulnerability to view the driver's license number and other personal information. | |
| Modificada | Media (5.5) | 0.35% | — | Jollytech Lobby Track | 21/3/2019 | 17/6/2026 | Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and clicking on reports, an attacker could exploit this vulnerability to gain access to all visitor records and obtain sensitive information. | |
| Modificada | Media (5.4) | 0.29% | — | Innopage Giga Hobby | 21/10/2014 | 17/6/2026 | The GIGA HOBBY (aka com.innopage.store.gigahobby) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Longluntan Gzonerc - THE RC Hobby HUB | 21/10/2014 | 17/6/2026 | The GzoneRC - The RC Hobby Hub (aka com.wGzoneRC) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Hobbylobby Hobby Lobby Stores | 9/9/2014 | 17/6/2026 | The Hobby Lobby Stores (aka com.hobbylobbystores.android) application 2.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.8) | 0.81% | — | Ubuntu Developers Obby | 10/2/2014 | 16/6/2026 | obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate. |