Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3672 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.13%—Samsung Wear OS10/10/202517/6/2026
Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.
AnalizadaMedia (4.4)0.13%—Samsung Android10/10/202517/6/2026
Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
AnalizadaAlta (7.1)0.12%—Samsung Notes10/10/20251/10/2026
Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
AnalizadaMedia (6.5)0.27%—Samsung Smart Switch10/10/202530/9/2026
Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.
AnalizadaMedia (5.5)0.10%—Samsung Smart Switch10/10/202530/9/2026
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability.
AplazadaAlta (7.5)0.34%—OpenindianaAISunosAI29/9/202517/6/2026
Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN flag set, Openindiana has a wide acceptable range of sequence numbers. It does not require the sequence number to exactly match the next expected sequence value, just to be within the current receive…
AplazadaAlta (7.5)0.31%—Oracle Sunos OmniosAI29/9/202517/6/2026
An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets.
AnalizadaAlta (7)0.23%—Lizardbyte Sunshine23/9/202517/6/2026
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a space, the Service Control Manager (SCM) interprets the path incrementally and may…
AplazadaAlta (8.6)0.18%—Wi-sunAI12/9/202517/6/2026
Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the middle (MitM) attack
ModificadaCrítica (9.8)2.1%⚠ Explotación activaSamsung Android12/9/20257/10/2026
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
En análisisCrítica (9.8)33%⚠ Explotación activa💥 PoCSamsung Android12/9/20257/10/2026
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
ModificadaAlta (7.8)0.19%—Lizardbyte Sunshine9/9/202517/6/2026
A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path.
ModificadaAlta (7.8)0.22%—Lizardbyte Sunshine9/9/202517/6/2026
Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories.
AnalizadaMedia (5.5)0.12%—Samsung Good Lock4/9/202517/6/2026
Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applications from Galaxy Store.
AplazadaMedia (4.3)0.15%—Samsung MiscpolicyAI4/9/202517/6/2026
Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to access to Proxy information.
AnalizadaMedia (5.5)0.13%—Samsung Android3/9/202517/6/2026
Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.
AnalizadaBaja (3.3)0.11%—Samsung Sassistant3/9/202517/6/2026
Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.
AnalizadaBaja (3.3)0.11%—Samsung Sassistant3/9/202517/6/2026
Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.
AnalizadaBaja (3.3)0.11%—Samsung Sassistant3/9/202517/6/2026
Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.
AnalizadaMedia (5)0.12%—Samsung Notes3/9/202517/6/2026
Improper access control in Samsung Notes prior to version 4.4.30.63 allows local privileged attackers to access exported note files. User interaction is required for triggering this vulnerability.
AnalizadaMedia (4.6)0.22%—Samsung Calendar3/9/202517/6/2026
Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles.
AnalizadaAlta (7.8)0.14%—Samsung Android3/9/202517/6/2026
Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.
AnalizadaMedia (5.5)0.12%—Samsung Android3/9/202517/6/2026
Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.
AnalizadaMedia (6.8)0.17%—Samsung Android3/9/202517/6/2026
Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.
AnalizadaMedia (6.8)0.14%—Samsung Android3/9/202517/6/2026
Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.