Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3672 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.55%—Samsung Smart Switch16/3/202617/6/2026
Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
AnalizadaMedia (5.3)0.26%—Samsung Smart Switch16/3/202617/6/2026
Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.
AnalizadaAlta (7.1)0.17%—Samsung Smart Switch16/3/202617/6/2026
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.
AnalizadaMedia (5.3)0.28%—Samsung Smart Switch16/3/202617/6/2026
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
AnalizadaMedia (6.9)0.12%—Samsung Account16/3/202617/6/2026
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
AnalizadaMedia (4.8)0.09%—Samsung Assistant16/3/202617/6/2026
Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information.
AnalizadaMedia (4.8)0.08%—Samsung Android16/3/202617/6/2026
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
AnalizadaMedia (6.7)0.12%—Samsung Android16/3/202617/6/2026
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
AnalizadaAlta (8.4)0.16%—Samsung Android16/3/202617/6/2026
Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege.
AnalizadaMedia (5.1)0.11%—Samsung Android16/3/202617/6/2026
Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.
AnalizadaMedia (6.8)0.08%—Samsung Android16/3/202617/6/2026
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability.
AnalizadaAlta (7.5)0.27%—Sunbirded-portal11/3/202617/6/2026
An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This allows attackers to obtain sensitive information
AnalizadaAlta (7.5)0.43%—Sunbirded-portal9/3/202617/6/2026
An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
AnalizadaAlta (8.8)0.16%—Sunbirded-portal9/3/202617/6/2026
An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
ModificadaAlta (7.5)0.35%—Sunbirded-portal9/3/202617/6/2026
An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
AnalizadaMedia (6.1)0.24%—Sunbirded-portal9/3/202617/6/2026
An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
AnalizadaMedia (5.4)0.24%—Sunbirded-portal9/3/202617/6/2026
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
AnalizadaMedia (5.5)0.11%—Samsung Exynos 1280 FirmwareSamsung Exynos 1380 FirmwareSamsung Exynos 1480 FirmwareSamsung Exynos 1580 Firmware+33/3/202617/6/2026
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4L_VERTEXIOC_BOOTUP input leads to a denial of service.
AnalizadaAlta (7.5)0.50%—Samsung Exynos 2200 Firmware3/3/202617/6/2026
An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization within DL NAS Transport messages.
AnalizadaMedia (5.5)0.15%—Samsung Exynos 1380 FirmwareSamsung Exynos 1480 FirmwareSamsung Exynos 1580 FirmwareSamsung Exynos 2400 Firmware+13/3/202617/6/2026
An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.ast.thread_ref in set_cpu_affinity() causes a denial of service.
AnalizadaAlta (7.5)0.50%—Samsung Exynos 1280 FirmwareSamsung Exynos 1380 FirmwareSamsung Exynos 1480 FirmwareSamsung Exynos 2200 Firmware+13/3/202617/6/2026
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference of ft_handle in load_fw_utc_vector() causes a denial of service.
ModificadaAlta (7.5)0.30%—Samsung Exynos 1280 FirmwareSamsung Exynos 1380 FirmwareSamsung Exynos 1480 FirmwareSamsung Exynos 1580 Firmware+33/3/202621/9/2026
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service.
Pendiente de análisisAlta (7.5)0.26%—Microsoft ExchangeAIMicrosoft Exchange ActivesyncAISamsung Mobile DevicesAI2/3/202617/6/2026
In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.
AplazadaMedia (5.3)0.25%—Samsung MultixpressAI20/2/202617/6/2026
Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing address book entries and other device configuration information through specific APIs without proper authorization.
AplazadaMedia (6.5)0.24%—Sunshinephotocart Sunshine Photo CartAI20/2/202617/6/2026
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.6.2.