Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

3671 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.08%—Samsung Visual Voicemail9/9/202623/9/2026
Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.
AnalizadaMedia (5.1)0.09%—Samsung Android9/9/202623/9/2026
Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.
AnalizadaMedia (6.9)0.09%—Samsung Bixby9/9/202623/9/2026
Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.
AnalizadaMedia (6.9)0.09%—Samsung Notes9/9/202623/9/2026
Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory.
AnalizadaMedia (5.9)0.09%—Samsung Collection9/9/202623/9/2026
Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.
AnalizadaMedia (6.9)0.09%—Samsung Android9/9/202628/9/2026
Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction.
AnalizadaMedia (4.8)0.11%—Samsung Android9/9/202628/9/2026
Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.
AplazadaMedia (6.2)0.17%—Samsung EscargotAI7/9/202628/9/2026
An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry count exceeds UINT16_MAX. This issue affects…
AplazadaMedia (6.2)0.18%—Samsung WalrusAI7/9/202628/9/2026
Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check.…
AplazadaAlta (7.8)0.17%—Samsung WalrusAI7/9/202628/9/2026
Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.
AplazadaMedia (4.4)0.15%—Samsung RlottieAI4/9/20268/9/2026
Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630.
AplazadaMedia (6.3)0.13%—Samsung TizenfxAI3/9/20268/9/2026
Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers.
AplazadaMedia (5.5)0.11%—Samsung MtowerAI1/9/20261/9/2026
Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.
AplazadaMedia (5.5)0.15%—Samsung MtowerAI1/9/20261/9/2026
Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.
AplazadaMedia (5.5)0.15%—Samsung MtowerAI1/9/20261/9/2026
NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.
AplazadaMedia (5.5)0.15%—Samsung RlottieAI31/8/20261/9/2026
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.
AplazadaAlta (8.5)0.58%—SuneditorAI26/8/20269/9/2026
SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the SunEditor Embed plugin in src/plugins/modal/embed.js parses attacker-controlled raw embed HTML with DOMParser and processes the resulting DOM nodes. When an external script element follows a valid…
AplazadaMedia (5.3)0.40%—Sunnyadn Js-tomlAI14/8/202618/9/2026
js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if (object[key])` instead of `if (key in object)`. When the prior value is a falsy primitive — `false`, `0`, `0n`, `0.0`, `-0`, or `""` — the duplicate-key branch is…
AnalizadaMedia (6.5)0.35%—Samsung Rlottie12/8/202630/9/2026
Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
AnalizadaMedia (6.5)0.36%—Samsung Rlottie12/8/202630/9/2026
Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
AnalizadaMedia (6.5)0.36%—Samsung Rlottie11/8/202623/9/2026
Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.
AnalizadaMedia (6.5)0.36%—Samsung Rlottie11/8/202623/9/2026
Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
Pendiente de análisisMedia (6.9)0.13%—Samsung SmartthingsAI10/8/202618/8/2026
Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.
AnalizadaMedia (6.8)0.26%—Samsung Smart Switch10/8/202619/8/2026
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
AnalizadaMedia (6.9)0.17%—Samsung Health10/8/202619/8/2026
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.