Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3672 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.25%—Samsung Magician2/9/202517/6/2026
An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process.
AplazadaCrítica (9.4)0.16%—Sunpower Pvs6AI2/9/202517/6/2026
The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly accessible protocol details. An attacker within Bluetooth range could exploit this vulnerability to gain full access to the device's servicing interface. This access allows the attacker to perform…
AnalizadaMedia (6.9)0.52%—Sun.net Ehrd Ctms1/9/202517/6/2026
The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.
AnalizadaMedia (5.1)0.26%—Sun.net Ehrd Ctms1/9/202517/6/2026
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
AnalizadaMedia (5.1)0.26%—Sun.net Ehrd Ctms1/9/202530/9/2026
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
AnalizadaMedia (5.1)0.26%—Sun.net Ehrd Ctms1/9/202530/9/2026
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
AplazadaCrítica (9.3)1.1%💥 ExploitSunwayland ForcecontrolAI30/8/202516/6/2026
Sunway ForceControl version 6.1 SP3 and earlier contains a stack-based buffer overflow vulnerability in the SNMP NetDBServer service, which listens on TCP port 2001. The flaw is triggered when the service receives a specially crafted packet using opcode 0x57 with an overly long payload. Due to improper bounds checking…
ModificadaCrítica (9.3)0.48%—Sun.net Ehrd Ctms30/8/202517/6/2026
A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.
ModificadaCrítica (10)0.54%—Sun.net Ehrd Ctms30/8/202517/6/2026
An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path.
ModificadaMedia (6.9)0.69%—Sun.net Ehrd Ctms30/8/202517/6/2026
An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a specific file, which may lead to arbitrary code execution.
ModificadaCrítica (9.3)0.50%—Sun.net Ehrd Ctms30/8/202517/6/2026
A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized application deployment due to the absence of proper access control checks.
ModificadaCrítica (9.3)0.47%—Sun.net Ehrd Ctms30/8/202517/6/2026
A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to access deployment functionality without prior authentication.
AplazadaMedia (6.5)0.67%—SMA Sunny BOYAI27/8/202517/6/2026
An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.
AplazadaMedia (5.4)0.24%—Cyclonedx SunshineAI13/8/202517/6/2026
CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file
AplazadaBaja (3.3)0.12%—Samsung Galaxy WatchAIGoogle Android WatchAI6/8/202517/6/2026
Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information.
AnalizadaMedia (5.5)0.12%—Samsung Galaxy Wearable6/8/202517/6/2026
Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.
AnalizadaMedia (6.7)0.13%—Samsung Blockchain Keystore6/8/202517/6/2026
Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
AnalizadaMedia (6.7)0.13%—Samsung Blockchain Keystore6/8/202517/6/2026
Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
AnalizadaMedia (5.5)0.14%—Samsung Health6/8/202517/6/2026
Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.
AnalizadaMedia (4.4)0.15%—Samsung Blockchain Keystore6/8/202517/6/2026
Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.
AnalizadaMedia (6.7)0.15%—Samsung Blockchain Keystore6/8/202517/6/2026
Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
AnalizadaAlta (7.1)0.15%—Samsung Android6/8/202517/6/2026
Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
AnalizadaMedia (5.5)0.13%—Samsung Android6/8/202517/6/2026
Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.
AplazadaMedia (6.2)0.14%—Samsung Galaxy WatchAI6/8/202517/6/2026
Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time.
AplazadaMedia (5.5)0.12%—Samsung Galaxy WatchAI6/8/202517/6/2026
Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration.