Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

195 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.21%—Samsung Galaxy Store12/7/202217/6/2026
Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
ModificadaAlta (7.8)0.21%—Samsung Galaxy Store12/7/202217/6/2026
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
ModificadaMedia (4.4)0.22%—Samsung Galaxy S22 Firmware3/5/202217/6/2026
Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.
ModificadaMedia (5.5)0.22%—Samsung Galaxy Store3/5/202217/6/2026
Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.
ModificadaMedia (5.5)0.25%—Redhat Ansible Automation PlatformRedhat Ansible Galaxy18/4/202217/6/2026
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and…
ModificadaAlta (7.8)0.27%—Samsung Galaxy Store11/4/202217/6/2026
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.
ModificadaMedia (5.5)0.90%—Samsung Galaxy Store11/4/202217/6/2026
Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.
ModificadaMedia (5.5)0.27%—Samsung Galaxy Store11/4/202217/6/2026
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.
ModificadaBaja (3.3)0.21%—Samsung Galaxy Watch 3 Plugin10/3/202217/6/2026
Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information of connected WiFiAp in the log
ModificadaBaja (3.3)0.21%—Samsung Galaxy Watch Plugin10/3/202217/6/2026
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information of connected WiFiAp in the log
ModificadaBaja (3.3)0.21%—Samsung Galaxy Watch 3 Plugin10/3/202217/6/2026
Information Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of connected WiFiAp in the log
ModificadaBaja (3.3)0.21%—Samsung Galaxy Watch Plugin10/3/202217/6/2026
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log.
ModificadaAlta (7.5)0.92%—Samsung Galaxy Store10/1/202217/6/2026
Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.
ModificadaMedia (5.5)0.22%—Samsung Galaxy Store6/10/202117/6/2026
Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provider of Galaxy Store.
ModificadaAlta (8.8)0.44%—Samsung Galaxy Watch Active 2 FirmwareSamsung Galaxy Watch Active FirmwareSamsung Galaxy Watch FirmwareSamsung Galaxy Watch 3 Firmware+511/6/202117/6/2026
Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.
ModificadaMedia (5.5)0.24%—Samsung Galaxy Watch 3 Plugin11/6/202117/6/2026
Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
ModificadaMedia (5.5)0.24%—Samsung Galaxy Watch Plugin11/6/202117/6/2026
Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
ModificadaMedia (5.3)5.6%—Samsung Galaxy I9305 FirmwareArista C-250 FirmwareArista C-260 FirmwareArista C-230 Firmware+1511/5/202117/6/2026
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP,…
ModificadaMedia (6.5)3.5%—Samsung Galaxy I9305 FirmwareSiemens 6gk5763-1al00-7da0 FirmwareSiemens 6gk5766-1ge00-7da0 FirmwareSiemens 6gk5766-1ge00-7db0 Firmware+911/5/202117/6/2026
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the…
ModificadaMedia (6.5)4.9%—Samsung Galaxy I9305 FirmwareArista C-250 FirmwareArista C-260 FirmwareArista C-230 Firmware+1411/5/202117/6/2026
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the…
ModificadaAlta (7.8)0.48%—GOG Galaxy30/4/202117/6/2026
GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally through unsigned DLL loading.
ModificadaAlta (7.1)0.21%—Samsung Galaxy Themes25/3/202117/6/2026
Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private file directories of Galaxy Themes application without permission via hijacking the PendingIntent.
ModificadaCrítica (9.8)3.5%—A10networks AgalaxyA10networks Advanced Core Operating System10/11/202017/6/2026
A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affected ACOS systems. ACOS versions 3.2.x (including and after 3.2.2), 4.x, and 5.1.x are affected. aGalaxy versions 3.0.x, 3.2.x, and 5.0.x are…
ModificadaAlta (7.8)0.62%—GOG Galaxy21/8/202017/6/2026
The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by instructing the Windows service to execute arbitrary commands. This occurs because the attacker can inject a DLL into GalaxyClient.exe,…
ModificadaAlta (8.8)3.8%💥 ExploitGOG Galaxy6/8/202017/6/2026
The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embedded, static RSA private key, an attacker with this key material and local user permissions can effectively send any operating system command to the service for execution…
Orbitaley — Vulnerabilidades