Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3672 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.13% | — | Samsung Wear OS | 10/10/2025 | 17/6/2026 | Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. | |
| Analizada | Media (4.4) | 0.13% | — | Samsung Android | 10/10/2025 | 17/6/2026 | Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Alta (7.1) | 0.12% | — | Samsung Notes | 10/10/2025 | 1/10/2026 | Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory. | |
| Analizada | Media (6.5) | 0.27% | — | Samsung Smart Switch | 10/10/2025 | 30/9/2026 | Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data. | |
| Analizada | Media (5.5) | 0.10% | — | Samsung Smart Switch | 10/10/2025 | 30/9/2026 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability. | |
| Aplazada | Alta (7.5) | 0.34% | — | OpenindianaAISunosAI | 29/9/2025 | 17/6/2026 | Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN flag set, Openindiana has a wide acceptable range of sequence numbers. It does not require the sequence number to exactly match the next expected sequence value, just to be within the current receive… | |
| Aplazada | Alta (7.5) | 0.31% | — | Oracle Sunos OmniosAI | 29/9/2025 | 17/6/2026 | An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets. | |
| Analizada | Alta (7) | 0.23% | — | Lizardbyte Sunshine | 23/9/2025 | 17/6/2026 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a space, the Service Control Manager (SCM) interprets the path incrementally and may… | |
| Aplazada | Alta (8.6) | 0.18% | — | Wi-sunAI | 12/9/2025 | 17/6/2026 | Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the middle (MitM) attack | |
| Modificada | Crítica (9.8) | 2.1% | ⚠ Explotación activa | Samsung Android | 12/9/2025 | 7/10/2026 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. | |
| En análisis | Crítica (9.8) | 33% | ⚠ Explotación activa💥 PoC | Samsung Android | 12/9/2025 | 7/10/2026 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.19% | — | Lizardbyte Sunshine | 9/9/2025 | 17/6/2026 | A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path. | |
| Modificada | Alta (7.8) | 0.22% | — | Lizardbyte Sunshine | 9/9/2025 | 17/6/2026 | Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories. | |
| Analizada | Media (5.5) | 0.12% | — | Samsung Good Lock | 4/9/2025 | 17/6/2026 | Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applications from Galaxy Store. | |
| Aplazada | Media (4.3) | 0.15% | — | Samsung MiscpolicyAI | 4/9/2025 | 17/6/2026 | Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to access to Proxy information. | |
| Analizada | Media (5.5) | 0.13% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Media (5) | 0.12% | — | Samsung Notes | 3/9/2025 | 17/6/2026 | Improper access control in Samsung Notes prior to version 4.4.30.63 allows local privileged attackers to access exported note files. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (4.6) | 0.22% | — | Samsung Calendar | 3/9/2025 | 17/6/2026 | Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles. | |
| Analizada | Alta (7.8) | 0.14% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code. | |
| Analizada | Media (5.5) | 0.12% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information. | |
| Analizada | Media (6.8) | 0.17% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions. | |
| Analizada | Media (6.8) | 0.14% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs. |