Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
–

1690 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.18%—Samsung Android6/7/202317/6/2026
Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
ModificadaAlta (7.8)0.19%—Samsung Android6/7/202317/6/2026
Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
ModificadaAlta (7.8)0.19%—Samsung Android6/7/202317/6/2026
Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
ModificadaAlta (7.8)0.19%—Samsung Android6/7/202317/6/2026
Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
ModificadaAlta (7.8)0.19%—Samsung Android6/7/202317/6/2026
Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
ModificadaAlta (7.8)0.20%—Samsung Android6/7/202317/6/2026
Heap out of bound write vulnerability in RmtUimNeedApdu of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
ModificadaMedia (5.5)0.17%—Samsung Android6/7/202317/6/2026
Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.
ModificadaAlta (7.8)0.20%—Samsung Android6/7/202317/6/2026
Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
ModificadaAlta (7.8)0.20%—Samsung Android6/7/202317/6/2026
Heap out of bound write vulnerability in BroadcastSmsConfig of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
ModificadaAlta (7.8)0.20%—Samsung Android6/7/202317/6/2026
Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
ModificadaAlta (7.8)0.20%—Samsung Android6/7/202317/6/2026
Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
ModificadaAlta (7.1)0.16%—Samsung Android6/7/202317/6/2026
Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications.
ModificadaMedia (5.5)0.14%—Samsung Android6/7/202317/6/2026
Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.
ModificadaMedia (4.3)0.25%—Samsung Android6/7/202317/6/2026
Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.
ModificadaBaja (3.3)0.14%—Samsung Android6/7/202317/6/2026
Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.
ModificadaAlta (7.8)0.21%—Samsung Searchwidget28/6/202317/6/2026
Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.
ModificadaCrítica (9.8)1.6%—Samsung Exynos28/6/202317/6/2026
Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execute arbitrary code.
ModificadaMedia (6.8)0.39%—Samsung Android28/6/202317/6/2026
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
ModificadaBaja (3.3)0.22%—Samsung Android28/6/202317/6/2026
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.
ModificadaCrítica (9.8)0.62%—Samsung Exynos 5123 FirmwareSamsung Exynos 5300 Firmware7/6/202317/6/2026
Se descubrió un problema en Shannon RCS component en Samsung Exynos Modem 5123 y 5300. Un permiso predeterminado incorrecto puede provocar una consulta no deseada de la capacidad RCS a través de una aplicación manipulada específicamente para ello.
ModificadaAlta (7.5)0.49%—Samsung Exynos 5123 FirmwareSamsung Exynos 5300 Firmware7/6/202317/6/2026
Se descubrió un problema en Shannon RCS component en Samsung Exynos Modem 5123 y 5300. La transferencia incorrecta de recursos entre esferas puede provocar cambios en el modo de activación de RCS a través de una aplicación manipulada específicamente para ello.
ModificadaCrítica (9.1)0.56%—Samsung Exynos 5123 FirmwareSamsung Exynos 5300 Firmware7/6/202317/6/2026
Se descubrió un problema en Shannon RCS component en Samsung Exynos Modem 5123 y 5300. La transferencia incorrecta de recursos entre esferas puede provocar una consulta no deseada del estado de la SIM a través de una aplicación manipulada específicamente para ello.
ModificadaCrítica (9.6)0.55%—Samsung Galaxy Store26/5/202317/6/2026
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
ModificadaAlta (8.8)0.52%—Samsung Galaxy Store26/5/202317/6/2026
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
ModificadaAlta (8.8)0.52%—Samsung Galaxy Store26/5/202317/6/2026
Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
Orbitaley — Vulnerabilidades