Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
9126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.27% | — | Google Android | 4/9/2025 | 17/6/2026 | In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (5.5) | 0.08% | — | Google Android | 4/9/2025 | 17/6/2026 | In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.5) | 0.18% | — | Google Android | 4/9/2025 | 17/6/2026 | Denial of service | |
| Analizada | Alta (8.8) | 0.22% | — | Google Android | 4/9/2025 | 17/6/2026 | Elevation of privilege | |
| Analizada | Crítica (9.8) | 0.24% | — | Google Android | 4/9/2025 | 17/6/2026 | Elevation of Privilege | |
| Analizada | Alta (7.8) | 0.08% | — | Google Android | 4/9/2025 | 17/6/2026 | In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.08% | — | Google Android | 4/9/2025 | 17/6/2026 | In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.5) | 0.27% | — | Google Android | 4/9/2025 | 17/6/2026 | In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure post authentication with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (4.2) | 0.32% | 💥 PoC | Donbermoy Android Corona Virus Tracker APP FOR India | 3/9/2025 | 17/6/2026 | The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. MD5 is a broken cryptographic algorithm known to allow hash collisions. This makes… | |
| Analizada | Media (5.5) | 0.13% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information. | |
| Analizada | Alta (7.8) | 0.14% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code. | |
| Analizada | Media (5.5) | 0.12% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information. | |
| Analizada | Media (6.8) | 0.17% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions. | |
| Analizada | Media (6.8) | 0.14% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs. | |
| Aplazada | Media (4.3) | 0.16% | — | Chinese Android 15AI | 3/9/2025 | 17/6/2026 | Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display. | |
| Analizada | Media (4.4) | 0.11% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call. | |
| Analizada | Media (4.4) | 0.12% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management. | |
| Analizada | Alta (7.8) | 0.13% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities. | |
| Analizada | Media (5.3) | 0.38% | — | Samsung AndroidSamsung Smart Suggestions | 3/9/2025 | 17/6/2026 | Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule. | |
| Analizada | Media (5.5) | 0.13% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data. | |
| Analizada | Media (5.5) | 0.14% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data. | |
| Analizada | Alta (7.8) | 0.16% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code. | |
| Analizada | Alta (7.8) | 0.16% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code. |