Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3672 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.25% | — | Samsung Magician | 2/9/2025 | 17/6/2026 | An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process. | |
| Aplazada | Crítica (9.4) | 0.16% | — | Sunpower Pvs6AI | 2/9/2025 | 17/6/2026 | The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly accessible protocol details. An attacker within Bluetooth range could exploit this vulnerability to gain full access to the device's servicing interface. This access allows the attacker to perform… | |
| Analizada | Media (6.9) | 0.52% | — | Sun.net Ehrd Ctms | 1/9/2025 | 17/6/2026 | The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files. | |
| Analizada | Media (5.1) | 0.26% | — | Sun.net Ehrd Ctms | 1/9/2025 | 17/6/2026 | The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Analizada | Media (5.1) | 0.26% | — | Sun.net Ehrd Ctms | 1/9/2025 | 30/9/2026 | The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Analizada | Media (5.1) | 0.26% | — | Sun.net Ehrd Ctms | 1/9/2025 | 30/9/2026 | The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Aplazada | Crítica (9.3) | 1.1% | 💥 Exploit | Sunwayland ForcecontrolAI | 30/8/2025 | 16/6/2026 | Sunway ForceControl version 6.1 SP3 and earlier contains a stack-based buffer overflow vulnerability in the SNMP NetDBServer service, which listens on TCP port 2001. The flaw is triggered when the service receives a specially crafted packet using opcode 0x57 with an overly long payload. Due to improper bounds checking… | |
| Modificada | Crítica (9.3) | 0.48% | — | Sun.net Ehrd Ctms | 30/8/2025 | 17/6/2026 | A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands. | |
| Modificada | Crítica (10) | 0.54% | — | Sun.net Ehrd Ctms | 30/8/2025 | 17/6/2026 | An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path. | |
| Modificada | Media (6.9) | 0.69% | — | Sun.net Ehrd Ctms | 30/8/2025 | 17/6/2026 | An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a specific file, which may lead to arbitrary code execution. | |
| Modificada | Crítica (9.3) | 0.50% | — | Sun.net Ehrd Ctms | 30/8/2025 | 17/6/2026 | A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized application deployment due to the absence of proper access control checks. | |
| Modificada | Crítica (9.3) | 0.47% | — | Sun.net Ehrd Ctms | 30/8/2025 | 17/6/2026 | A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to access deployment functionality without prior authentication. | |
| Aplazada | Media (6.5) | 0.67% | — | SMA Sunny BOYAI | 27/8/2025 | 17/6/2026 | An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices. | |
| Aplazada | Media (5.4) | 0.24% | — | Cyclonedx SunshineAI | 13/8/2025 | 17/6/2026 | CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file | |
| Aplazada | Baja (3.3) | 0.12% | — | Samsung Galaxy WatchAIGoogle Android WatchAI | 6/8/2025 | 17/6/2026 | Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information. | |
| Analizada | Media (5.5) | 0.12% | — | Samsung Galaxy Wearable | 6/8/2025 | 17/6/2026 | Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information. | |
| Analizada | Media (6.7) | 0.13% | — | Samsung Blockchain Keystore | 6/8/2025 | 17/6/2026 | Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Media (6.7) | 0.13% | — | Samsung Blockchain Keystore | 6/8/2025 | 17/6/2026 | Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Media (5.5) | 0.14% | — | Samsung Health | 6/8/2025 | 17/6/2026 | Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (4.4) | 0.15% | — | Samsung Blockchain Keystore | 6/8/2025 | 17/6/2026 | Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory. | |
| Analizada | Media (6.7) | 0.15% | — | Samsung Blockchain Keystore | 6/8/2025 | 17/6/2026 | Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Alta (7.1) | 0.15% | — | Samsung Android | 6/8/2025 | 17/6/2026 | Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege. | |
| Analizada | Media (5.5) | 0.13% | — | Samsung Android | 6/8/2025 | 17/6/2026 | Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information. | |
| Aplazada | Media (6.2) | 0.14% | — | Samsung Galaxy WatchAI | 6/8/2025 | 17/6/2026 | Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time. | |
| Aplazada | Media (5.5) | 0.12% | — | Samsung Galaxy WatchAI | 6/8/2025 | 17/6/2026 | Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration. |