Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

3672 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)10%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.50%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaAlta (8.8)9.0%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.61%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0
AplazadaCrítica (9.3)0.97%—Samsung Wea453eAI15/7/202517/6/2026
An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.2.4.T1 via improper input validation in the “Tech Support” diagnostic functionality. The command1 and command2 POST or GET parameters accept arbitrary shell commands that are executed with root…
AnalizadaMedia (5.5)0.13%—Samsung Android8/7/202517/6/2026
Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
AnalizadaMedia (5.5)0.13%—Samsung Android8/7/202517/6/2026
Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
AnalizadaMedia (5.5)0.13%—Samsung Android8/7/202517/6/2026
Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
AnalizadaAlta (7.8)0.13%—Samsung Android8/7/202517/6/2026
Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.
AnalizadaMedia (5.5)0.13%—Samsung Android8/7/202517/6/2026
Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.
AnalizadaMedia (5.5)0.09%—Samsung Wear OS8/7/202517/6/2026
Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.
AnalizadaMedia (5.5)0.14%—Samsung Android8/7/202517/6/2026
Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.
AnalizadaMedia (5.5)0.12%—Samsung Android8/7/202517/6/2026
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.
AnalizadaMedia (5.5)0.13%—Samsung Android8/7/202517/6/2026
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.
AnalizadaBaja (3.3)0.13%—Samsung Android8/7/202517/6/2026
Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.
AnalizadaBaja (2.1)0.17%—Samsung Android8/7/202517/6/2026
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.
AnalizadaBaja (3.3)0.13%—Samsung Wear OS8/7/202517/6/2026
Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.
AnalizadaMedia (5.5)0.13%—Samsung Wear OS8/7/202517/6/2026
Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.
AnalizadaMedia (6.7)0.13%—Samsung Android8/7/202517/6/2026
Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
AnalizadaMedia (6.7)0.13%—Samsung Android8/7/202517/6/2026
Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
AnalizadaCrítica (9.1)0.41%—Samsung Exynos 980 FirmwareSamsung Exynos 990 FirmwareSamsung Exynos 850 FirmwareSamsung Exynos 2100 Firmware+157/7/202517/6/2026
In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400, the lack of a length check leads to out-of-bounds writes.
AnalizadaAlta (7.5)0.36%—Samsung Exynos 2400 FirmwareSamsung Modem 5400 Firmware7/7/202517/6/2026
An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a Denial of Service via a malformed PDCP packet.
AnalizadaMedia (6.1)0.24%—Lizardbyte Sunshine1/7/202517/6/2026
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a malicious website using an invisible or disguised iframe. If a user is tricked…
AnalizadaAlta (8.8)0.24%—Lizardbyte Sunshine1/7/202517/6/2026
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to craft a malicious web page that, when visited by an authenticated user, can trigger unintended…
AnalizadaMedia (5.1)0.39%—Samsung Rlottie30/6/202517/6/2026
Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.