Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
1690 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Media (5.1) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Media (5.1) | 0.21% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. | |
| Analizada | Media (5.1) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Alta (8.4) | 0.17% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. | |
| Analizada | Media (5.1) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Media (5.1) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Media (4.8) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Alta (7) | 0.12% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. | |
| Analizada | Media (6.8) | 0.20% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. | |
| Analizada | Media (4.8) | 0.09% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. | |
| Analizada | Media (6) | 0.41% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (6.7) | 0.21% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. | |
| Analizada | Media (6.9) | 0.13% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. | |
| Analizada | Media (6.9) | 0.14% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. | |
| Analizada | Media (6.5) | 0.36% | — | Samsung Rlottie | 4/8/2026 | 23/9/2026 | Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion. | |
| Aplazada | Alta (7.1) | 0.47% | — | Samsung CaptureAI | 15/7/2026 | 16/7/2026 | PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture objects running within the same Python process could share state, including HTTP headers, cookies, browser storage, HTTP credentials, proxy… | |
| Analizada | Media (5.5) | 0.11% | — | Samsung Rlottie | 12/7/2026 | 2/10/2026 | Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects . | |
| Aplazada | Media (5.3) | 0.47% | — | Samsung MembersAI | 11/7/2026 | 14/7/2026 | The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest. This makes it possible for unauthenticated attackers to extract determine the existence and exact count… | |
| Aplazada | Media (6.8) | 0.15% | — | Samsung PassAI | 10/7/2026 | 10/7/2026 | Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory. | |
| Aplazada | Media (4.8) | 0.13% | — | Samsung HealthAI | 10/7/2026 | 10/7/2026 | Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device information. | |
| Aplazada | Alta (8.5) | 0.17% | 💥 PoC | Samsung BixbyAI | 10/7/2026 | 11/7/2026 | Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege. | |
| Aplazada | Media (5.1) | 0.16% | — | Samsung EmailAI | 10/7/2026 | 10/7/2026 | Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within the application sandbox. | |
| Aplazada | Media (6.8) | 0.16% | — | Samsung SemclipboardserviceAI | 10/7/2026 | 14/7/2026 | Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege. | |
| Aplazada | Media (5.1) | 0.15% | — | Samsung SmartthingskitAI | 10/7/2026 | 10/7/2026 | Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. |