Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1690 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.18% | — | Samsung Android | 10/10/2025 | 17/6/2026 | Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code. | |
| Analizada | Media (6.8) | 0.19% | — | Samsung Android | 10/10/2025 | 17/6/2026 | Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs. | |
| Analizada | Baja (2.4) | 0.16% | — | Samsung Android | 10/10/2025 | 17/6/2026 | Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent app list. | |
| Analizada | Media (5.5) | 0.13% | — | Samsung Wear OS | 10/10/2025 | 17/6/2026 | Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. | |
| Analizada | Media (4.4) | 0.13% | — | Samsung Android | 10/10/2025 | 17/6/2026 | Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Alta (7.1) | 0.12% | — | Samsung Notes | 10/10/2025 | 1/10/2026 | Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory. | |
| Analizada | Media (6.5) | 0.27% | — | Samsung Smart Switch | 10/10/2025 | 30/9/2026 | Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data. | |
| Analizada | Media (5.5) | 0.10% | — | Samsung Smart Switch | 10/10/2025 | 30/9/2026 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability. | |
| Modificada | Crítica (9.8) | 2.1% | ⚠ Explotación activa | Samsung Android | 12/9/2025 | 7/10/2026 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. | |
| En análisis | Crítica (9.8) | 33% | ⚠ Explotación activa💥 PoC | Samsung Android | 12/9/2025 | 7/10/2026 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. | |
| Analizada | Media (5.5) | 0.12% | — | Samsung Good Lock | 4/9/2025 | 17/6/2026 | Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applications from Galaxy Store. | |
| Aplazada | Media (4.3) | 0.15% | — | Samsung MiscpolicyAI | 4/9/2025 | 17/6/2026 | Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to access to Proxy information. | |
| Analizada | Media (5.5) | 0.13% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Media (5) | 0.12% | — | Samsung Notes | 3/9/2025 | 17/6/2026 | Improper access control in Samsung Notes prior to version 4.4.30.63 allows local privileged attackers to access exported note files. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (4.6) | 0.22% | — | Samsung Calendar | 3/9/2025 | 17/6/2026 | Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles. | |
| Analizada | Alta (7.8) | 0.14% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code. | |
| Analizada | Media (5.5) | 0.12% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information. | |
| Analizada | Media (6.8) | 0.17% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions. | |
| Analizada | Media (6.8) | 0.14% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display. | |
| Analizada | Media (4.4) | 0.11% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call. |