Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

3672 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.27%—Sunshinephotocart Sunshine Photo CartAI27/10/202517/6/2026
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.3.
AplazadaCrítica (9.1)0.47%—Gesundheit-bewegt ZippyAI22/10/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy zippy allows Using Malicious Files.This issue affects Zippy: from n/a through <= 1.7.0.
AnalizadaMedia (4.3)0.28%—Samsung Exynos 980 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 1280 FirmwareSamsung Exynos 1330 Firmware+620/10/202517/6/2026
In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000, there is an improper access control vulnerability related to a log file.
AnalizadaAlta (7.5)0.60%—Samsung Exynos W920 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 990 Firmware+1120/10/202517/6/2026
An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 9110, W920, W930, Modem 5123, and Modem 5300. Incorrect handling of RLC AM PDUs leads to a Denial of Service.
AnalizadaAlta (7.5)0.60%—Samsung Exynos W920 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 990 Firmware+920/10/202517/6/2026
An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 9110, W920, W930, Modem 5123, and Modem 5300. Incorrect handling of RLC AM PDUs leads to a Denial of Service.
AnalizadaAlta (7.5)0.60%—Samsung Exynos 1080 FirmwareSamsung Exynos 1330 FirmwareSamsung Exynos 1380 FirmwareSamsung Exynos 1480 Firmware+1420/10/202517/6/2026
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The absence of a NULL check leads to a Denial of Service when an attacker sends malformed MM packets to…
AnalizadaMedia (5.5)0.12%—Samsung Notes10/10/202517/6/2026
Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.
AnalizadaAlta (7.1)0.12%—Samsung Notes10/10/202517/6/2026
Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
AnalizadaAlta (7.1)0.12%—Samsung Notes10/10/202517/6/2026
Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
AnalizadaAlta (7.1)0.12%—Samsung Notes10/10/202517/6/2026
Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
AnalizadaMedia (4.6)0.17%—Samsung Voice Recorder10/10/202517/6/2026
Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen.
AnalizadaAlta (7.8)0.10%—Samsung Smart Switch10/10/202517/6/2026
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.
AnalizadaMedia (5.5)0.10%—Samsung Smart Switch10/10/202517/6/2026
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.
AnalizadaMedia (5.5)0.12%—Samsung Health10/10/202517/6/2026
Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.
AnalizadaBaja (3.3)0.11%—Samsung Notes10/10/202517/6/2026
Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes.
AnalizadaAlta (7.5)0.29%—Samsung Android10/10/202517/6/2026
Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.
AnalizadaMedia (5.5)0.12%—Samsung Android10/10/202517/6/2026
Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.
AnalizadaAlta (7.8)0.13%—Samsung Android10/10/202517/6/2026
Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.
AnalizadaAlta (7.8)0.13%—Samsung Android10/10/202517/6/2026
Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.
AnalizadaAlta (7.8)0.13%—Samsung Android10/10/202517/6/2026
Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.
AnalizadaMedia (5.5)0.13%—Samsung Android10/10/202517/6/2026
Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.
AnalizadaMedia (5.5)0.14%—Samsung Android10/10/202517/6/2026
Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
AnalizadaAlta (7.8)0.18%—Samsung Android10/10/202517/6/2026
Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code.
AnalizadaMedia (6.8)0.19%—Samsung Android10/10/202517/6/2026
Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.
AnalizadaBaja (2.4)0.16%—Samsung Android10/10/202517/6/2026
Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent app list.