Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1690 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.13% | — | Samsung Wear OS | 8/7/2025 | 17/6/2026 | Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch. | |
| Analizada | Media (6.7) | 0.13% | — | Samsung Android | 8/7/2025 | 17/6/2026 | Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Media (6.7) | 0.13% | — | Samsung Android | 8/7/2025 | 17/6/2026 | Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Crítica (9.1) | 0.41% | — | Samsung Exynos 980 FirmwareSamsung Exynos 990 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 2100 Firmware+15 | 7/7/2025 | 17/6/2026 | In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400, the lack of a length check leads to out-of-bounds writes. | |
| Analizada | Alta (7.5) | 0.36% | — | Samsung Exynos 2400 FirmwareSamsung Modem 5400 Firmware | 7/7/2025 | 17/6/2026 | An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a Denial of Service via a malformed PDCP packet. | |
| Analizada | Media (5.1) | 0.39% | — | Samsung Rlottie | 30/6/2025 | 17/6/2026 | Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2. | |
| Analizada | Media (5.1) | 0.39% | — | Samsung Rlottie | 30/6/2025 | 17/6/2026 | Out-of-bounds Read vulnerability in Samsung Open Source rLottie allows Overflow Buffers.This issue affects rLottie: V0.2. | |
| Analizada | Media (4.6) | 0.28% | — | Samsung Rlottie | 30/6/2025 | 17/6/2026 | Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2. | |
| Modificada | Media (5.1) | 0.51% | — | Samsung Rlottie | 30/6/2025 | 17/6/2026 | Use After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2. | |
| Analizada | Media (6.5) | 0.24% | — | Samsung Exynos 2200 FirmwareSamsung Exynos 1480 FirmwareSamsung Exynos 2400 Firmware | 4/6/2025 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation. | |
| Analizada | Media (6.5) | 0.24% | — | Samsung Exynos 1380 Firmware | 4/6/2025 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor Exynos 1380. A Use-After-Free in the mobile processor leads to privilege escalation. | |
| Analizada | Media (6.5) | 0.24% | — | Samsung Exynos 1280 FirmwareSamsung Exynos 2200 FirmwareSamsung Exynos 1380 FirmwareSamsung Exynos 1480 Firmware+1 | 4/6/2025 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation. | |
| Analizada | Media (6.5) | 0.24% | — | Samsung Exynos 1280 FirmwareSamsung Exynos 2200 FirmwareSamsung Exynos 1380 FirmwareSamsung Exynos 1480 Firmware+1 | 4/6/2025 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation. | |
| Analizada | Media (5) | 0.13% | — | Samsung Smart Switch | 4/6/2025 | 17/6/2026 | Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers to read data with the privilege of Smart Switch. User interaction is required for triggering this vulnerability. | |
| Analizada | Alta (7.1) | 0.12% | — | Samsung Internet | 4/6/2025 | 17/6/2026 | Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to read and write arbitrary files. | |
| Analizada | Alta (7.1) | 0.11% | — | Samsung Internet | 4/6/2025 | 17/6/2026 | Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to access read and write arbitrary files. | |
| Analizada | Media (6.8) | 0.14% | — | Samsung Android | 4/6/2025 | 17/6/2026 | Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Alta (7.7) | 0.15% | — | Samsung Android | 4/6/2025 | 17/6/2026 | Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory. | |
| Analizada | Media (5.1) | 0.13% | — | Samsung Android | 4/6/2025 | 17/6/2026 | Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable. | |
| Analizada | Media (5.2) | 0.14% | — | Samsung Android | 4/6/2025 | 17/6/2026 | Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac_key. | |
| Analizada | Alta (7.1) | 0.15% | — | Samsung Android | 4/6/2025 | 17/6/2026 | Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory. | |
| Analizada | Media (6.7) | 0.14% | — | Samsung Android | 4/6/2025 | 17/6/2026 | Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a auth_token. | |
| Analizada | Media (5.5) | 0.14% | — | Samsung Wear OS | 4/6/2025 | 17/6/2026 | Improper access control in ScreenCapture for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to take screenshots. | |
| Analizada | Baja (3.3) | 0.12% | — | Samsung Android | 4/6/2025 | 17/6/2026 | Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items. | |
| Analizada | Media (6.2) | 0.14% | — | Samsung Wear OS | 4/6/2025 | 17/6/2026 | Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to access data in Samsung Cloud for Galaxy Watch. |