Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

9126 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.09%💥 PoCSamsung Android13/5/202617/6/2026
Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.
AnalizadaMedia (6.8)0.15%💥 PoCSamsung Android13/5/202617/6/2026
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.
AnalizadaMedia (5.1)0.09%💥 PoCSamsung Android13/5/202617/6/2026
Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
AnalizadaMedia (6.8)0.09%💥 PoCSamsung Android13/5/202617/6/2026
Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.
AplazadaAlta (8.6)0.41%—Meari IOT SDKAIMeari CloudedgeAIArentiAIMeari Android APPAI11/5/202617/6/2026
In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys.
AnalizadaAlta (7.5)0.30%—Google Android6/5/202625/7/2026
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
AnalizadaAlta (7.5)0.31%—Google Android6/5/202620/7/2026
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
AnalizadaAlta (7.5)0.32%—Google Android6/5/202620/7/2026
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
AnalizadaAlta (7.5)0.32%—Google Android6/5/202625/7/2026
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
AnalizadaAlta (7.5)0.33%—Google Android6/5/202620/7/2026
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
AnalizadaAlta (7.5)0.30%—Google Android6/5/202625/7/2026
In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
AnalizadaAlta (8.8)0.54%💥 PoCGoogle Android4/5/202617/6/2026
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaMedia (6.9)0.10%—Samsung Android29/4/202617/6/2026
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
AnalizadaMedia (6.8)0.09%💥 PoCSamsung Android13/4/202617/6/2026
External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.
AnalizadaMedia (5.4)0.15%💥 PoCSamsung Android13/4/202617/6/2026
Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.
AnalizadaAlta (7.8)0.10%💥 PoCSamsung Android13/4/202617/6/2026
Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.
AnalizadaMedia (4.1)0.23%💥 PoCSamsung Android13/4/202617/6/2026
Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.
AnalizadaMedia (5.1)0.16%💥 PoCSamsung Android13/4/202617/6/2026
Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.
AnalizadaMedia (4.4)0.16%💥 PoCSamsung Android13/4/202617/6/2026
Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.
AnalizadaMedia (4.7)0.13%💥 PoCSamsung Android13/4/202617/6/2026
Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.
AnalizadaMedia (5.2)0.16%💥 PoCSamsung Android13/4/202617/6/2026
Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions.
Pendiente de análisisCrítica (9.1)0.46%💥 PoCJXL 9 Inch CAR Android Double DIN PlayerAI7/4/202624/7/2026
An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.
AnalizadaMedia (6.2)0.10%💥 PoCGoogle Android6/4/202624/7/2026
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
ModificadaMedia (5.5)0.10%—Google Android6/4/20268/9/2026
In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Pendiente de análisisAlta (7.8)0.52%—Tecno Pova7 PRO 5GAIGoogle AndroidAI2/4/202617/6/2026
Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as system via command injection.