Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3672 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.29% | — | Sunbirded-portal | 11/2/2026 | 17/6/2026 | An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTP request options | |
| Analizada | Media (5.1) | 0.17% | — | Samsung Members | 4/2/2026 | 17/6/2026 | Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members. | |
| Analizada | Alta (7) | 0.32% | — | Samsung Members | 4/2/2026 | 17/6/2026 | Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability. | |
| Aplazada | Media (5.1) | 0.16% | — | Samsung Galaxy WearableAI | 4/2/2026 | 17/6/2026 | Improper handling of insufficient permission in Galaxy Wearable installed on non-Samsung Device prior to version 2.2.68 allows local attackers to access sensitive information. | |
| Analizada | Alta (8.4) | 0.14% | — | Samsung Android | 4/2/2026 | 17/6/2026 | Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege. | |
| Analizada | Media (6.8) | 0.34% | — | Samsung Android | 4/2/2026 | 17/6/2026 | Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege. | |
| Analizada | Media (5.4) | 0.22% | — | Samsung Android | 4/2/2026 | 17/6/2026 | Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege. | |
| Analizada | Alta (7) | 0.26% | 💥 PoC | Samsung Android | 4/2/2026 | 17/6/2026 | Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands. | |
| Analizada | Alta (8.4) | 0.14% | — | Samsung Android | 4/2/2026 | 17/6/2026 | Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege. | |
| Analizada | Media (5.8) | 0.13% | — | Samsung Android | 4/2/2026 | 17/6/2026 | Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. | |
| Analizada | Media (6.9) | 0.14% | — | Samsung Android | 4/2/2026 | 17/6/2026 | Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning. | |
| Analizada | Alta (7.5) | 0.47% | — | Samsung Exynos 990 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 9110 FirmwareSamsung Exynos 1080 Firmware+5 | 3/2/2026 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920, W930, W1000 and Modem 5123. Incorrect handling of NAS Registration messages leads to a Denial of Service because of Improper Handling of Exceptional Conditions. | |
| Modificada | Media (5.5) | 0.15% | — | Samsung Exynos 980 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+7 | 3/2/2026 | 17/6/2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/confg_tspec write operation, leading to kernel memory exhaustion. | |
| Modificada | Media (5.5) | 0.15% | — | Samsung Exynos 980 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+7 | 3/2/2026 | 17/6/2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/p2p_certif write operation, leading to kernel memory exhaustion. | |
| Modificada | Media (5.5) | 0.13% | — | Samsung Exynos 980 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+7 | 3/2/2026 | 17/6/2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_addts write operation, leading to kernel memory exhaustion. | |
| Modificada | Media (5.5) | 0.13% | — | Samsung Exynos 980 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+7 | 3/2/2026 | 17/6/2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_certif_11ax_mode write operation, leading to kernel memory… | |
| Analizada | Media (6.2) | 0.17% | — | Samsung Exynos 980 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+7 | 3/2/2026 | 17/6/2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation in a /proc/driver/unifi0/conn_log_event_burst_to_us write operation, leading to kernel memory exhaustion. | |
| Modificada | Media (5.5) | 0.15% | — | Samsung Exynos 980 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+7 | 3/2/2026 | 17/6/2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/create_tspec write operation, leading to kernel memory exhaustion. | |
| Analizada | Media (6.2) | 0.17% | — | Samsung Exynos 980 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+7 | 3/2/2026 | 17/6/2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/uapsd write operation, leading to kernel memory exhaustion. | |
| Analizada | Media (6.2) | 0.17% | — | Samsung Exynos 980 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+7 | 3/2/2026 | 17/6/2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_cert_disable_ht_vht write operation, leading to kernel memory… | |
| Analizada | Media (6.2) | 0.17% | — | Samsung Exynos 980 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+7 | 3/2/2026 | 17/6/2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_delts write operation, leading to kernel memory exhaustion. | |
| Aplazada | Media (5.3) | 0.22% | — | Sunshinephotocart Sunshine Photo CartAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.2. | |
| Analizada | Crítica (9.8) | 0.48% | — | Samsung Magicinfo 9 Server | 2/2/2026 | 17/6/2026 | The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1. | |
| Analizada | Alta (8.8) | 0.45% | — | Samsung Magicinfo 9 Server | 2/2/2026 | 17/6/2026 | An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1. | |
| Analizada | Crítica (9.8) | 0.55% | — | Samsung Magicinfo 9 Server | 2/2/2026 | 17/6/2026 | A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1. |