Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
9126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.11% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege. | |
| Analizada | Media (6.8) | 0.23% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader. | |
| Analizada | Media (6.8) | 0.23% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader. | |
| Analizada | Baja (3.3) | 0.13% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission. | |
| Analizada | Baja (3.3) | 0.12% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action. | |
| Analizada | Baja (3.3) | 0.12% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action. | |
| Analizada | Alta (7.8) | 0.13% | — | Samsung Android | 3/9/2025 | 17/6/2026 | Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission. | |
| Analizada | Baja (3.3) | 0.08% | — | Samsung Android | 3/9/2025 | 17/6/2026 | PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission. | |
| Analizada | Media (5.5) | 0.11% | — | Samsung Android | 3/9/2025 | 30/9/2026 | Gestión inadecuada de privilegios en ThemeManager anterior a SMR Sep-2025 Release 1 permite a atacantes locales privilegiados reutilizar elementos de prueba. | |
| Analizada | Crítica (9.8) | 0.56% | — | Google Android | 2/9/2025 | 17/6/2026 | In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7) | 0.07% | 💥 PoC | Google Android | 2/9/2025 | 17/6/2026 | In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications into a newly created work profile due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | |
| Analizada | Alta (7.3) | 0.08% | — | Google Android | 2/9/2025 | 17/6/2026 | In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| Analizada | Crítica (9.8) | 0.24% | — | Google Android | 2/9/2025 | 17/6/2026 | In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.09% | — | Google Android | 2/9/2025 | 17/6/2026 | In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 2/9/2025 | 17/6/2026 | In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most commonly used in Work Profile scenarios due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | |
| Analizada | Media (5.5) | 0.08% | — | Google Android | 2/9/2025 | 17/6/2026 | In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic error in the code. This could lead to local denial of service until the phone reboots with no additional execution privileges needed. User interaction is not needed for… | |
| Analizada | Media (5.5) | 0.10% | — | Google Android | 2/9/2025 | 17/6/2026 | In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Crítica (9.8) | 0.24% | — | Google Android | 2/9/2025 | 17/6/2026 | In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.08% | — | Google Android | 2/9/2025 | 17/6/2026 | In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the primary user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… | |
| Analizada | Alta (7.3) | 0.09% | — | Google Android | 2/9/2025 | 17/6/2026 | In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| Analizada | Alta (7.5) | 0.30% | — | Google Android | 2/9/2025 | 17/6/2026 | In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 2/9/2025 | 17/6/2026 | In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app when its result will be used in another due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed… | |
| Analizada | Media (5.5) | 0.10% | — | Google Android | 2/9/2025 | 17/6/2026 | In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak through the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.3) | 0.08% | — | Google Android | 2/9/2025 | 17/6/2026 | In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. | |
| Analizada | Alta (7.8) | 0.08% | — | Google Android | 2/9/2025 | 17/6/2026 | In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |