Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.58% | — | Schneider-electric Galaxy VL FirmwareSchneider-electric Galaxy VS Firmware | 15/11/2023 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS. | |
| Modificada | Alta (8.8) | 0.21% | — | Galaxyweblinks Video Playlist FOR Youtube | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Video Playlist For YouTube plugin <= 6.0 versions. | |
| Modificada | Alta (7.8) | 0.17% | — | Samsung Galaxy Book FirmwareSamsung Galaxy Book PRO FirmwareSamsung Galaxy Book PRO 360 FirmwareSamsung Galaxy Book Odyssey Firmware | 4/10/2023 | 17/6/2026 | An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey allows local attacker to execute SMM memory corruption. | |
| Modificada | Media (4.3) | 0.39% | — | Galaxyproject Galaxy | 22/9/2023 | 17/6/2026 | Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side request forgery, which allows a malicious to issue arbitrary HTTP/HTTPS requests from the application server to internal hosts and read their responses. Version 22.05 contains a patch for this issue. | |
| Modificada | Media (5.5) | 0.15% | — | Samsung Galaxy Store | 10/8/2023 | 17/6/2026 | Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Galaxy Book GO FirmwareSamsung Galaxy Book GO 5G FirmwareSamsung Galaxy Book2 GO FirmwareSamsung Galaxy Book2 PRO 360 Firmware | 10/8/2023 | 17/6/2026 | Stack overflow vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Galaxy Book GO FirmwareSamsung Galaxy Book GO 5G FirmwareSamsung Galaxy Book2 GO FirmwareSamsung Galaxy Book2 PRO 360 Firmware | 10/8/2023 | 17/6/2026 | Out-of-bounds Write vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code. | |
| Modificada | Crítica (9.6) | 0.55% | — | Samsung Galaxy Store | 26/5/2023 | 17/6/2026 | XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. | |
| Modificada | Alta (8.8) | 0.52% | — | Samsung Galaxy Store | 26/5/2023 | 17/6/2026 | InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. | |
| Modificada | Alta (8.8) | 0.52% | — | Samsung Galaxy Store | 26/5/2023 | 17/6/2026 | Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. | |
| Modificada | Baja (3.9) | 0.36% | — | Samsung Galaxy S21 Firmware | 28/3/2023 | 17/6/2026 | This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to 4.5.40.5 phones. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Media (5.4) | 0.38% | — | Galaxyweblinks Gallery With Thumbnail Slider | 21/3/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <= 6.0 versions. | |
| Modificada | Alta (7.5) | 0.77% | — | Galaxyproject Galaxy | 20/3/2023 | 17/6/2026 | Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as the functionality of Visualizations/Pages exists. Due to this issue, an attacker… | |
| Modificada | Media (6.1) | 13% | — | Samsung Galaxy Store | 9/2/2023 | 17/6/2026 | Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page. | |
| Modificada | Alta (7.8) | 3.7% | — | Samsung Galaxy Store | 9/2/2023 | 17/6/2026 | Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store. | |
| Modificada | Crítica (9.8) | 0.89% | — | Galaxyproject Galaxy | 17/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in galaxy-data-resource up to 14.10.0. This affects an unknown part of the component Command Line Template. The manipulation leads to injection. Upgrading to version 14.10.1 is able to address this issue. The patch is named… | |
| Modificada | Alta (7.5) | 0.85% | — | Galaxyproject Galaxy | 6/12/2022 | 17/6/2026 | Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, which can be used to read any file accessible to the operating system user under which Galaxy is running. This vulnerability affects Galaxy 22.01 and higher, after the… | |
| Modificada | Baja (3.3) | 0.22% | — | Samsung Galaxy Buds PRO Manage | 9/11/2022 | 17/6/2026 | Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log. | |
| Modificada | Baja (3.3) | 0.17% | — | Samsung Galaxywatch4plugin | 9/11/2022 | 17/6/2026 | Improper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows attackers to access wearable device information. | |
| Modificada | Media (5.5) | 0.20% | — | Samsung Galaxy Watch Plugin | 9/9/2022 | 17/6/2026 | Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission. | |
| Modificada | Media (6.2) | 0.20% | — | Samsung Galaxy Watch Plugin | 9/9/2022 | 17/6/2026 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number. | |
| Modificada | Media (6.5) | 0.23% | — | Samsung Galaxy Watch Plugin | 9/9/2022 | 17/6/2026 | Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device. | |
| Modificada | Alta (7.8) | 0.51% | 💥 PoC | GOG Galaxy | 17/8/2022 | 17/6/2026 | An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM. | |
| Modificada | Media (4.6) | 0.20% | — | Samsung Galaxy Wearable | 5/8/2022 | 17/6/2026 | Implicit Intent hijacking vulnerability in Galaxy Wearable prior to version 2.2.50 allows attacker to get sensitive information. | |
| Modificada | Alta (7.8) | 0.21% | — | Samsung Galaxy Store | 12/7/2022 | 17/6/2026 | Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege. |