Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1690 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.7)0.13%—Samsung Blockchain Keystore6/8/202517/6/2026
Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
AnalizadaMedia (6.7)0.13%—Samsung Blockchain Keystore6/8/202517/6/2026
Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
AnalizadaMedia (5.5)0.14%—Samsung Health6/8/202517/6/2026
Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.
AnalizadaMedia (4.4)0.15%—Samsung Blockchain Keystore6/8/202517/6/2026
Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.
AnalizadaMedia (6.7)0.15%—Samsung Blockchain Keystore6/8/202517/6/2026
Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
AnalizadaAlta (7.1)0.15%—Samsung Android6/8/202517/6/2026
Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
AnalizadaMedia (5.5)0.13%—Samsung Android6/8/202517/6/2026
Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.
AplazadaMedia (6.2)0.14%—Samsung Galaxy WatchAI6/8/202517/6/2026
Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time.
AplazadaMedia (5.5)0.12%—Samsung Galaxy WatchAI6/8/202517/6/2026
Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration.
AplazadaMedia (5.5)0.13%—Samsung Galaxy WatchAI6/8/202517/6/2026
Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to motion and body sensors.
AnalizadaMedia (6)0.13%—Samsung Android6/8/202517/6/2026
Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.
AnalizadaBaja (3.3)0.12%—Samsung Android6/8/202517/6/2026
Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.
AnalizadaMedia (6.5)0.21%—Samsung Exynos 2100 FirmwareSamsung Exynos 2200 FirmwareSamsung Exynos 2400 FirmwareSamsung Exynos 1280 Firmware+34/8/202517/6/2026
An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leads to an out-of-bound write.
AnalizadaCrítica (9.1)0.47%—Samsung Data Management Server Firmware29/7/202517/6/2026
An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.
AnalizadaCrítica (9.1)0.39%—Samsung Data Management Server Firmware29/7/202517/6/2026
An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.
AnalizadaMedia (6.5)0.34%—Samsung Data Management Server Firmware29/7/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem
AnalizadaMedia (4.9)0.46%—Samsung Data Management Server Firmware29/7/202517/6/2026
Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files
AnalizadaCrítica (9.8)0.38%—Samsung Data Management Server Firmware29/7/202517/6/2026
Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system
AnalizadaMedia (6.5)0.31%—Samsung Data Management Server Firmware29/7/202517/6/2026
An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability.
AnalizadaCrítica (9.8)0.55%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.54%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)24%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.39%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.65%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.59%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.