Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
9104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7) | 0.07% | — | Android BluetoothAI | 5/10/2026 | 6/10/2026 | In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Pendiente de análisis | Alta (8.8) | 0.23% | — | Android BluetoothAI | 5/10/2026 | 6/10/2026 | In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Pendiente de análisis | Media (5.5) | 0.06% | — | AndroidAI | 5/10/2026 | 6/10/2026 | In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Pendiente de análisis | Alta (7.8) | 0.07% | — | Google AndroidAI | 5/10/2026 | 6/10/2026 | In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Pendiente de análisis | Alta (7.8) | 0.07% | — | Android LibufdtAI | 5/10/2026 | 6/10/2026 | In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Pendiente de análisis | Alta (7.8) | 0.12% | — | AndroidAI | 5/10/2026 | 6/10/2026 | In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Recibida | Media (6.7) | 0.11% | — | Android AidlAI | 5/10/2026 | 6/10/2026 | In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11242428; Issue ID: MSV-9038. | |
| Pendiente de análisis | Media (5.3) | 0.32% | — | Wikimedia Wikipedia Android APPAI | 25/9/2026 | 28/9/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: main. | |
| Pendiente de análisis | Media (6.9) | 0.19% | — | Verizon Cloud FOR AndroidAI | 17/9/2026 | 22/9/2026 | Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplying a crafted _display_name value containing path-traversal sequences through… | |
| Analizada | Alta (8.8) | 0.59% | ⚠ Explotación activa | Google Android | 15/9/2026 | 17/9/2026 | In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.09% | — | Google Android | 15/9/2026 | 18/9/2026 | In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7) | 0.07% | — | Google Android | 15/9/2026 | 18/9/2026 | In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.2) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7) | 0.07% | — | Google Android | 15/9/2026 | 18/9/2026 | In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7) | 0.07% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (4.4) | 0.09% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. |