Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

78 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)13%—Samsung Galaxy Store9/2/202317/6/2026
Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page.
ModificadaAlta (7.8)3.7%—Samsung Galaxy Store9/2/202317/6/2026
Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.
ModificadaAlta (7.8)0.21%—Samsung Galaxy Store12/7/202217/6/2026
Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
ModificadaAlta (7.8)0.21%—Samsung Galaxy Store12/7/202217/6/2026
Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
ModificadaAlta (7.8)0.21%—Samsung Galaxy Store12/7/202217/6/2026
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
ModificadaMedia (4.4)0.22%—Samsung Galaxy S22 Firmware3/5/202217/6/2026
Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.
ModificadaMedia (5.5)0.22%—Samsung Galaxy Store3/5/202217/6/2026
Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.
ModificadaAlta (7.8)0.27%—Samsung Galaxy Store11/4/202217/6/2026
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.
ModificadaMedia (5.5)0.90%—Samsung Galaxy Store11/4/202217/6/2026
Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.
ModificadaMedia (5.5)0.27%—Samsung Galaxy Store11/4/202217/6/2026
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.
ModificadaAlta (7.5)0.92%—Samsung Galaxy Store10/1/202217/6/2026
Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.
ModificadaMedia (5.5)0.22%—Samsung Galaxy Store6/10/202117/6/2026
Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provider of Galaxy Store.
ModificadaCrítica (9.8)1.5%—Samsung Galaxy S5 Firmware7/4/202017/6/2026
An issue was discovered on Samsung Galaxy S5 mobile devices with software through 2016-12-20 (Qualcomm AP chipsets). There are multiple buffer overflows in the bootloader. The Samsung ID is SVE-2016-7930 (March 2017).
ModificadaMedia (5.5)1.3%💥 ExploitSamsung Galaxy S6 Edge Firmware12/2/202017/6/2026
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter.
ModificadaMedia (4.3)0.29%—Samsung Galaxy S3 FirmwareSamsung Galaxy S4 Firmware27/12/201916/6/2026
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
ModificadaMedia (4.6)0.35%—Samsung Galaxy S3 FirmwareSamsung Galaxy S4 Firmware27/12/201916/6/2026
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.
ModificadaAlta (7.8)0.31%—Samsung Galaxy S7 Edge Firmware14/11/201917/6/2026
The Samsung S7 Edge Android device with a build fingerprint of samsung/hero2ltexx/hero2lte:8.0.0/R16NW/G935FXXS4ESC3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy S7 Edge Firmware14/11/201917/6/2026
The Samsung S7 Edge Android device with a build fingerprint of samsung/hero2ltexx/hero2lte:8.0.0/R16NW/G935FXXS4ESC3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy S7 Edge Firmware14/11/201917/6/2026
The Samsung S7 Edge Android device with a build fingerprint of samsung/hero2ltexx/hero2lte:8.0.0/R16NW/G935FXXS4ESC3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy S7 Firmware14/11/201917/6/2026
The Samsung S7 Android device with a build fingerprint of samsung/heroltexx/herolte:8.0.0/R16NW/G930FXXU3ESAC:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy S7 Firmware14/11/201917/6/2026
The Samsung S7 Android device with a build fingerprint of samsung/heroltexx/herolte:8.0.0/R16NW/G930FXXS4ESC3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy S7 Firmware14/11/201917/6/2026
The Samsung S7 Android device with a build fingerprint of samsung/heroltexx/herolte:8.0.0/R16NW/G930FXXS4ESC3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app…
ModificadaMedia (6.5)0.51%—Samsung Galaxy S8 Plus FirmwareSamsung Galaxy S3 FirmwareSamsung Galaxy Note 2 Firmware6/11/201917/6/2026
Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon 835, Baseband: G955USQU5CRG3), Samsung Galaxy S3 (Android version: 4.3, Build Number: JSS15J.I9300XXUGND5, Baseband Vendor: Samsung Exynos 4412, Baseband: I9300XXUGNA8), and Samsung Galaxy Note 2…
ModificadaMedia (6.5)0.46%—Samsung Galaxy S8 Plus FirmwareSamsung Galaxy S3 FirmwareSamsung Galaxy Note 2 Firmware6/11/201917/6/2026
Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon 835, Baseband: G955USQU5CRG3), Samsung Galaxy S3 (Android version: 4.3, Build Number: JSS15J.I9300XXUGND5, Baseband Vendor: Samsung Exynos 4412, Baseband: I9300XXUGNA8), and Samsung Galaxy Note 2…
ModificadaMedia (6.8)0.40%—Samsung Galaxy S10 FirmwareSamsung Note 10 Firmware17/10/201917/6/2026
Samsung Galaxy S10 and Note10 devices allow unlock operations via unregistered fingerprints in certain situations involving a third-party screen protector.
Orbitaley — Vulnerabilidades