Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3672 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.13% | — | Samsung Galaxy WatchAI | 6/8/2025 | 17/6/2026 | Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to motion and body sensors. | |
| Analizada | Media (6) | 0.13% | — | Samsung Android | 6/8/2025 | 17/6/2026 | Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account. | |
| Analizada | Baja (3.3) | 0.12% | — | Samsung Android | 6/8/2025 | 17/6/2026 | Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier. | |
| Analizada | Alta (7.9) | 0.50% | — | Sunnyadn Js-toml | 5/8/2025 | 17/6/2026 | js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype pollution vulnerability in js-toml allows a remote attacker to add or modify properties of the global Object.prototype by parsing a maliciously crafted TOML input. This is fixed in version 1.0.2. | |
| Analizada | Media (6.5) | 0.21% | — | Samsung Exynos 2100 FirmwareSamsung Exynos 2200 FirmwareSamsung Exynos 2400 FirmwareSamsung Exynos 1280 Firmware+3 | 4/8/2025 | 17/6/2026 | An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leads to an out-of-bound write. | |
| Analizada | Crítica (9.1) | 0.47% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses. | |
| Analizada | Crítica (9.1) | 0.39% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses. | |
| Analizada | Media (6.5) | 0.34% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem | |
| Analizada | Media (4.9) | 0.46% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files | |
| Analizada | Crítica (9.8) | 0.38% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system | |
| Analizada | Media (6.5) | 0.31% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability. | |
| Analizada | Crítica (9.8) | 0.55% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.54% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 24% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.39% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.65% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.59% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.63% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.60% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.46% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.61% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0 | |
| Analizada | Crítica (9.8) | 12% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.60% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.57% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0 | |
| Analizada | Crítica (9.8) | 0.47% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |