Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.14% | — | Samsung Galaxy Store | 8/4/2025 | 17/6/2026 | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store. | |
| Aplazada | Media (6.5) | 0.40% | — | Galaxyweblinks Video Playlist FOR YoutubeAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube video-playlist-for-youtube allows Stored XSS.This issue affects Video Playlist For YouTube: from n/a through <= 6.7.1. | |
| Aplazada | Media (5.3) | 0.37% | — | Galaxyweblinks WP Clone ANY Post TypeAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Clone any post type: from n/a through <= 3.6. | |
| Aplazada | Media (4.7) | 0.36% | — | Galaxyweblinks WP Clone ANY Post TypeAI | 1/4/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Phishing.This issue affects WP Clone any post type: from n/a through <= 3.6. | |
| Aplazada | Media (4) | 0.12% | — | Samsung Galaxy WearableAI | 6/3/2025 | 17/6/2026 | Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary activity with Galaxy Wearable privilege. | |
| Analizada | Media (4.6) | 0.20% | — | Samsung Galaxy Store | 4/2/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard. | |
| Aplazada | Media (5.5) | 0.15% | — | Samsung Galaxy WatchAI | 3/12/2024 | 17/6/2026 | Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch. | |
| Analizada | Media (6.7) | 0.13% | — | Samsung Galaxy S24 Firmware | 6/11/2024 | 17/6/2026 | Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability. | |
| Analizada | Media (6.7) | 0.13% | — | Samsung Galaxy S24 Firmware | 6/11/2024 | 17/6/2026 | Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability. | |
| Analizada | Crítica (9.1) | 0.45% | — | Galaxyproject Galaxy | 20/9/2024 | 17/6/2026 | Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or tampering. All supported branches of Galaxy (and more back to… | |
| Analizada | Media (5.4) | 0.77% | 💥 PoC | Galaxyproject Galaxy | 20/9/2024 | 17/6/2026 | Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon edit operation. All supported branches of… | |
| Analizada | Media (5.4) | 0.29% | — | Webdzier Hotel Galaxy | 18/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in webdzier Hotel Galaxy allows Stored XSS.This issue affects Hotel Galaxy: from n/a through 4.4.24. | |
| Aplazada | Alta (7) | 0.19% | — | Samsung Galaxy Smarttag2AI | 10/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes to potentially identify the tag's location by scanning the BLE adversting. | |
| Analizada | Media (5.3) | 0.13% | — | Samsung Galaxy Store | 2/7/2024 | 17/6/2026 | Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore. | |
| Analizada | Alta (7.5) | 0.30% | — | Samsung Galaxy Buds Manager | 4/6/2024 | 17/6/2026 | Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary directory. | |
| Analizada | Media (5.5) | 0.14% | — | Samsung Galaxy Store | 7/5/2024 | 17/6/2026 | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store. | |
| Aplazada | Media (6.5) | 0.68% | — | GOG GalaxyAI | 30/4/2024 | 17/6/2026 | An issue exists in GalaxyClientService.exe in GOG Galaxy (Beta) 2.0.67.2 through 2.0.71.2 that could allow authenticated users to overwrite and corrupt critical system files via a combination of an NTFS Junction and an RPC Object Manager symbolic link and could result in a denial of service. | |
| Aplazada | Media (6.7) | 0.70% | — | GOG GalaxyAI | 30/4/2024 | 17/6/2026 | A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentictaed users to change the DACL of arbitrary system directories to include Everyone full control permissions by modifying the FixDirectoryPrivileges instruction parameters sent from… | |
| Analizada | Media (5.1) | 0.15% | — | Samsung Galaxy Themes | 2/4/2024 | 17/6/2026 | Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrary files to sandbox of ThemeStore. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Galaxy Store | 6/2/2024 | 17/6/2026 | Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Galaxy Store | 6/2/2024 | 17/6/2026 | Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Galaxy Store | 6/2/2024 | 17/6/2026 | Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Galaxy Store | 6/2/2024 | 17/6/2026 | Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. | |
| Modificada | Alta (7.5) | 1.2% | — | Samsung Galaxy Store | 5/12/2023 | 17/6/2026 | Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data. | |
| Modificada | Crítica (9.8) | 0.97% | — | Samsung Galaxy Store | 5/12/2023 | 17/6/2026 | Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store. |