Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3672 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.55% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication. | |
| Analizada | Media (5.3) | 0.26% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication. | |
| Analizada | Alta (7.1) | 0.17% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication. | |
| Analizada | Media (5.3) | 0.28% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration. | |
| Analizada | Media (6.9) | 0.12% | — | Samsung Account | 16/3/2026 | 17/6/2026 | URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token. | |
| Analizada | Media (4.8) | 0.09% | — | Samsung Assistant | 16/3/2026 | 17/6/2026 | Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information. | |
| Analizada | Media (4.8) | 0.08% | — | Samsung Android | 16/3/2026 | 17/6/2026 | Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application. | |
| Analizada | Media (6.7) | 0.12% | — | Samsung Android | 16/3/2026 | 17/6/2026 | Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents. | |
| Analizada | Alta (8.4) | 0.16% | — | Samsung Android | 16/3/2026 | 17/6/2026 | Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege. | |
| Analizada | Media (5.1) | 0.11% | — | Samsung Android | 16/3/2026 | 17/6/2026 | Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font. | |
| Analizada | Media (6.8) | 0.08% | — | Samsung Android | 16/3/2026 | 17/6/2026 | Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability. | |
| Analizada | Alta (7.5) | 0.27% | — | Sunbirded-portal | 11/3/2026 | 17/6/2026 | An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This allows attackers to obtain sensitive information | |
| Analizada | Alta (7.5) | 0.43% | — | Sunbirded-portal | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | |
| Analizada | Alta (8.8) | 0.16% | — | Sunbirded-portal | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | |
| Modificada | Alta (7.5) | 0.35% | — | Sunbirded-portal | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | |
| Analizada | Media (6.1) | 0.24% | — | Sunbirded-portal | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | |
| Analizada | Media (5.4) | 0.24% | — | Sunbirded-portal | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | |
| Analizada | Media (5.5) | 0.11% | — | Samsung Exynos 1280 FirmwareSamsung Exynos 1380 FirmwareSamsung Exynos 1480 FirmwareSamsung Exynos 1580 Firmware+3 | 3/3/2026 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4L_VERTEXIOC_BOOTUP input leads to a denial of service. | |
| Analizada | Alta (7.5) | 0.50% | — | Samsung Exynos 2200 Firmware | 3/3/2026 | 17/6/2026 | An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization within DL NAS Transport messages. | |
| Analizada | Media (5.5) | 0.15% | — | Samsung Exynos 1380 FirmwareSamsung Exynos 1480 FirmwareSamsung Exynos 1580 FirmwareSamsung Exynos 2400 Firmware+1 | 3/3/2026 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.ast.thread_ref in set_cpu_affinity() causes a denial of service. | |
| Analizada | Alta (7.5) | 0.50% | — | Samsung Exynos 1280 FirmwareSamsung Exynos 1380 FirmwareSamsung Exynos 1480 FirmwareSamsung Exynos 2200 Firmware+1 | 3/3/2026 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference of ft_handle in load_fw_utc_vector() causes a denial of service. | |
| Modificada | Alta (7.5) | 0.30% | — | Samsung Exynos 1280 FirmwareSamsung Exynos 1380 FirmwareSamsung Exynos 1480 FirmwareSamsung Exynos 1580 Firmware+3 | 3/3/2026 | 21/9/2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service. | |
| Pendiente de análisis | Alta (7.5) | 0.26% | — | Microsoft ExchangeAIMicrosoft Exchange ActivesyncAISamsung Mobile DevicesAI | 2/3/2026 | 17/6/2026 | In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password. | |
| Aplazada | Media (5.3) | 0.25% | — | Samsung MultixpressAI | 20/2/2026 | 17/6/2026 | Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing address book entries and other device configuration information through specific APIs without proper authorization. | |
| Aplazada | Media (6.5) | 0.24% | — | Sunshinephotocart Sunshine Photo CartAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.6.2. |