Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
3671 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.08% | — | Samsung Visual Voicemail | 9/9/2026 | 23/9/2026 | Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission. | |
| Analizada | Media (5.1) | 0.09% | — | Samsung Android | 9/9/2026 | 23/9/2026 | Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (6.9) | 0.09% | — | Samsung Bixby | 9/9/2026 | 23/9/2026 | Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information. | |
| Analizada | Media (6.9) | 0.09% | — | Samsung Notes | 9/9/2026 | 23/9/2026 | Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory. | |
| Analizada | Media (5.9) | 0.09% | — | Samsung Collection | 9/9/2026 | 23/9/2026 | Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information. | |
| Analizada | Media (6.9) | 0.09% | — | Samsung Android | 9/9/2026 | 28/9/2026 | Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction. | |
| Analizada | Media (4.8) | 0.11% | — | Samsung Android | 9/9/2026 | 28/9/2026 | Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration. | |
| Aplazada | Media (6.2) | 0.17% | — | Samsung EscargotAI | 7/9/2026 | 28/9/2026 | An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry count exceeds UINT16_MAX. This issue affects… | |
| Aplazada | Media (6.2) | 0.18% | — | Samsung WalrusAI | 7/9/2026 | 28/9/2026 | Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check.… | |
| Aplazada | Alta (7.8) | 0.17% | — | Samsung WalrusAI | 7/9/2026 | 28/9/2026 | Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7. | |
| Aplazada | Media (4.4) | 0.15% | — | Samsung RlottieAI | 4/9/2026 | 8/9/2026 | Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630. | |
| Aplazada | Media (6.3) | 0.13% | — | Samsung TizenfxAI | 3/9/2026 | 8/9/2026 | Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers. | |
| Aplazada | Media (5.5) | 0.11% | — | Samsung MtowerAI | 1/9/2026 | 1/9/2026 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be. | |
| Aplazada | Media (5.5) | 0.15% | — | Samsung MtowerAI | 1/9/2026 | 1/9/2026 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e. | |
| Aplazada | Media (5.5) | 0.15% | — | Samsung MtowerAI | 1/9/2026 | 1/9/2026 | NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a. | |
| Aplazada | Media (5.5) | 0.15% | — | Samsung RlottieAI | 31/8/2026 | 1/9/2026 | Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51. | |
| Aplazada | Alta (8.5) | 0.58% | — | SuneditorAI | 26/8/2026 | 9/9/2026 | SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the SunEditor Embed plugin in src/plugins/modal/embed.js parses attacker-controlled raw embed HTML with DOMParser and processes the resulting DOM nodes. When an external script element follows a valid… | |
| Aplazada | Media (5.3) | 0.40% | — | Sunnyadn Js-tomlAI | 14/8/2026 | 18/9/2026 | js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if (object[key])` instead of `if (key in object)`. When the prior value is a falsy primitive — `false`, `0`, `0n`, `0.0`, `-0`, or `""` — the duplicate-key branch is… | |
| Analizada | Media (6.5) | 0.35% | — | Samsung Rlottie | 12/8/2026 | 30/9/2026 | Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. | |
| Analizada | Media (6.5) | 0.36% | — | Samsung Rlottie | 12/8/2026 | 30/9/2026 | Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation. | |
| Analizada | Media (6.5) | 0.36% | — | Samsung Rlottie | 11/8/2026 | 23/9/2026 | Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation. | |
| Analizada | Media (6.5) | 0.36% | — | Samsung Rlottie | 11/8/2026 | 23/9/2026 | Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation. | |
| Pendiente de análisis | Media (6.9) | 0.13% | — | Samsung SmartthingsAI | 10/8/2026 | 18/8/2026 | Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. | |
| Analizada | Media (6.8) | 0.26% | — | Samsung Smart Switch | 10/8/2026 | 19/8/2026 | Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | |
| Analizada | Media (6.9) | 0.17% | — | Samsung Health | 10/8/2026 | 19/8/2026 | Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. |