Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
9126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.4) | 0.14% | — | Samsung Android | 4/2/2026 | 17/6/2026 | Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege. | |
| Analizada | Media (5.8) | 0.13% | — | Samsung Android | 4/2/2026 | 17/6/2026 | Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. | |
| Analizada | Media (6.9) | 0.14% | — | Samsung Android | 4/2/2026 | 17/6/2026 | Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning. | |
| Analizada | Media (5.3) | 0.09% | — | Google Android | 2/2/2026 | 17/6/2026 | In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10314946 / ALPS10340155; Issue ID: MSV-5154. | |
| Analizada | Media (5.5) | 0.06% | — | Google Android | 2/2/2026 | 17/6/2026 | In imgsys, there is a possible memory corruption due to improper locking. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10363254; Issue ID: MSV-5617. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 2/2/2026 | 17/6/2026 | In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10362999; Issue ID: MSV-5625. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 2/2/2026 | 17/6/2026 | In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10362725; Issue ID: MSV-5694. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 2/2/2026 | 17/6/2026 | In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10351676; Issue ID: MSV-5733. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 2/2/2026 | 17/6/2026 | In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10351676; Issue ID: MSV-5737. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 2/2/2026 | 17/6/2026 | In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10362552; Issue ID: MSV-5760. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 2/2/2026 | 17/6/2026 | In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10363246; Issue ID: MSV-5779. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 16/1/2026 | 17/6/2026 | In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Modificada | Alta (7.1) | 8.5% | 💥 PoC | Google Android | 15/1/2026 | 17/6/2026 | In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (5.2) | 0.19% | — | Samsung Android | 9/1/2026 | 17/6/2026 | Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock. | |
| Analizada | Crítica (9.1) | 0.46% | — | Samsung Android | 9/1/2026 | 17/6/2026 | Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory. | |
| Analizada | Media (4.8) | 0.13% | — | Samsung Android | 9/1/2026 | 17/6/2026 | Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB. | |
| Analizada | Alta (7.3) | 0.17% | — | Samsung Android | 9/1/2026 | 17/6/2026 | Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code. | |
| Analizada | Media (6.8) | 0.14% | — | Samsung Android | 9/1/2026 | 17/6/2026 | Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs. | |
| Analizada | Baja (2.3) | 0.28% | — | Samsung Android | 9/1/2026 | 17/6/2026 | Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (6.7) | 0.17% | — | Samsung Android | 9/1/2026 | 17/6/2026 | Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code. | |
| Analizada | Media (6.7) | 0.15% | — | Google Android | 6/1/2026 | 7/10/2026 | In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114841; Issue ID: MSV-4451. | |
| Analizada | Media (6.7) | 0.14% | — | Google Android | 6/1/2026 | 7/10/2026 | In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114835; Issue ID: MSV-4479. | |
| Analizada | Media (6.7) | 0.14% | — | Google Android | 6/1/2026 | 7/10/2026 | In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114696; Issue ID: MSV-4480. | |
| Analizada | Media (6.7) | 0.14% | — | Google Android | 6/1/2026 | 7/10/2026 | In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10198951; Issue ID: MSV-4503. | |
| Analizada | Media (6.7) | 0.15% | — | Google Android | 6/1/2026 | 7/10/2026 | In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10199779; Issue ID: MSV-4504. |