Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

195 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.14%—Samsung Galaxy Store8/4/202517/6/2026
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
AplazadaMedia (6.5)0.40%—Galaxyweblinks Video Playlist FOR YoutubeAI4/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube video-playlist-for-youtube allows Stored XSS.This issue affects Video Playlist For YouTube: from n/a through <= 6.7.1.
AplazadaMedia (5.3)0.37%—Galaxyweblinks WP Clone ANY Post TypeAI1/4/202517/6/2026
Missing Authorization vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Clone any post type: from n/a through <= 3.6.
AplazadaMedia (4.7)0.36%—Galaxyweblinks WP Clone ANY Post TypeAI1/4/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Phishing.This issue affects WP Clone any post type: from n/a through <= 3.6.
AplazadaMedia (4)0.12%—Samsung Galaxy WearableAI6/3/202517/6/2026
Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary activity with Galaxy Wearable privilege.
AnalizadaMedia (4.6)0.20%—Samsung Galaxy Store4/2/202517/6/2026
Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.
AplazadaMedia (5.5)0.15%—Samsung Galaxy WatchAI3/12/202417/6/2026
Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.
AnalizadaMedia (6.7)0.13%—Samsung Galaxy S24 Firmware6/11/202417/6/2026
Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.
AnalizadaMedia (6.7)0.13%—Samsung Galaxy S24 Firmware6/11/202417/6/2026
Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.
AnalizadaCrítica (9.1)0.45%—Galaxyproject Galaxy20/9/202417/6/2026
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or tampering. All supported branches of Galaxy (and more back to…
AnalizadaMedia (5.4)0.77%💥 PoCGalaxyproject Galaxy20/9/202417/6/2026
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon edit operation. All supported branches of…
AnalizadaMedia (5.4)0.29%—Webdzier Hotel Galaxy18/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in webdzier Hotel Galaxy allows Stored XSS.This issue affects Hotel Galaxy: from n/a through 4.4.24.
AplazadaAlta (7)0.19%—Samsung Galaxy Smarttag2AI10/7/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes to potentially identify the tag's location by scanning the BLE adversting.
AnalizadaMedia (5.3)0.13%—Samsung Galaxy Store2/7/202417/6/2026
Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore.
AnalizadaAlta (7.5)0.30%—Samsung Galaxy Buds Manager4/6/202417/6/2026
Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary directory.
AnalizadaMedia (5.5)0.14%—Samsung Galaxy Store7/5/202417/6/2026
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
AplazadaMedia (6.5)0.68%—GOG GalaxyAI30/4/202417/6/2026
An issue exists in GalaxyClientService.exe in GOG Galaxy (Beta) 2.0.67.2 through 2.0.71.2 that could allow authenticated users to overwrite and corrupt critical system files via a combination of an NTFS Junction and an RPC Object Manager symbolic link and could result in a denial of service.
AplazadaMedia (6.7)0.70%—GOG GalaxyAI30/4/202417/6/2026
A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentictaed users to change the DACL of arbitrary system directories to include Everyone full control permissions by modifying the FixDirectoryPrivileges instruction parameters sent from…
AnalizadaMedia (5.1)0.15%—Samsung Galaxy Themes2/4/202417/6/2026
Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrary files to sandbox of ThemeStore.
ModificadaMedia (5.5)0.17%—Samsung Galaxy Store6/2/202417/6/2026
Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
ModificadaMedia (5.5)0.17%—Samsung Galaxy Store6/2/202417/6/2026
Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
ModificadaMedia (5.5)0.17%—Samsung Galaxy Store6/2/202417/6/2026
Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
ModificadaMedia (5.5)0.17%—Samsung Galaxy Store6/2/202417/6/2026
Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
ModificadaAlta (7.5)1.2%—Samsung Galaxy Store5/12/202317/6/2026
Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.
ModificadaCrítica (9.8)0.97%—Samsung Galaxy Store5/12/202317/6/2026
Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.
Orbitaley — Vulnerabilidades