Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
9126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.16% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Crítica (9.8) | 0.50% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Media (6.1) | 0.24% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Alta (7.5) | 0.44% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Alta (7.5) | 0.44% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Alta (7.5) | 0.27% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | Integer Overflow or Wraparound vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Crítica (9.8) | 0.41% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10. | |
| Analizada | Alta (7.5) | 0.27% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | NULL Pointer Dereference vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10. | |
| Aplazada | Media (4.4) | 0.33% | — | Androidbubbles Keep Backup DailyAI | 21/3/2026 | 17/6/2026 | The Keep Backup Daily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup title alias (`val` parameter) in the `update_kbd_bkup_alias` AJAX action in all versions up to, and including, 2.1.2. This is due to insufficient input sanitization and output escaping. While `sanitize_text_field()`… | |
| Aplazada | Baja (2.7) | 0.42% | — | Androidbubbles Keep Backup DailyAI | 21/3/2026 | 17/6/2026 | The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and including, 2.1.1 via the `kbd_open_upload_dir` AJAX action. This is due to insufficient validation of the `kbd_path` parameter, which is only sanitized with `sanitize_text_field()` - a function that does not… | |
| Analizada | Media (4.8) | 0.08% | — | Samsung Android | 16/3/2026 | 17/6/2026 | Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application. | |
| Analizada | Media (6.7) | 0.12% | — | Samsung Android | 16/3/2026 | 17/6/2026 | Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents. | |
| Analizada | Alta (8.4) | 0.16% | — | Samsung Android | 16/3/2026 | 17/6/2026 | Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege. | |
| Analizada | Media (5.1) | 0.11% | — | Samsung Android | 16/3/2026 | 17/6/2026 | Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font. | |
| Analizada | Media (6.8) | 0.08% | — | Samsung Android | 16/3/2026 | 17/6/2026 | Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability. | |
| Analizada | Crítica (10) | 0.14% | — | Google Android | 10/3/2026 | 17/6/2026 | There is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (8.4) | 0.07% | — | Google Android | 10/3/2026 | 17/6/2026 | In EfwApTransport::ProcessRxRing of efw_ap_transport.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (8.4) | 0.10% | — | Google Android | 10/3/2026 | 17/6/2026 | In multiple places, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Modificada | Baja (2.9) | 0.06% | — | Google Android | 10/3/2026 | 17/6/2026 | In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Crítica (9.8) | 0.32% | — | Google Android | 10/3/2026 | 17/6/2026 | In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.8) | 0.10% | — | Google Android | 10/3/2026 | 17/6/2026 | In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (8.4) | 0.09% | — | Google Android | 10/3/2026 | 17/6/2026 | In oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (8.4) | 0.08% | — | Google Android | 10/3/2026 | 17/6/2026 | In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Crítica (9.8) | 0.32% | — | Google Android | 10/3/2026 | 17/6/2026 | In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Baja (2.1) | 0.09% | — | Google Android | 10/3/2026 | 17/6/2026 | In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could lead to physical information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. |