Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

3672 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.44%—Silabs Wi-sun Software Development KIT21/3/202317/6/2026
Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network.
ModificadaMedia (5.5)0.19%—Samsung Bixbytouch16/3/202317/6/2026
Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files.
ModificadaBaja (3.3)0.14%—Samsung Calendar16/3/202317/6/2026
Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status.
ModificadaBaja (3.3)0.15%—Samsung Myfiles16/3/202317/6/2026
Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific conditions.
ModificadaBaja (3.3)0.16%—Samsung Quick Share16/3/202317/6/2026
The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.
ModificadaMedia (5.5)0.15%—Samsung Android16/3/202317/6/2026
Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
ModificadaMedia (4.4)0.16%—Samsung Android16/3/202317/6/2026
Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
ModificadaCrítica (9.8)0.27%—Samsung Android16/3/202317/6/2026
Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.
ModificadaBaja (3.3)0.15%—Samsung Android16/3/202317/6/2026
Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
ModificadaAlta (8.1)0.17%—Samsung Android16/3/202317/6/2026
Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.
ModificadaMedia (5.5)0.22%—Samsung Android16/3/202317/6/2026
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
ModificadaCrítica (9.1)0.40%—Samsung Exynos Firmware16/3/202317/6/2026
Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.
ModificadaBaja (2.4)0.23%—Samsung Android16/3/202317/6/2026
Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen.
ModificadaMedia (5.5)0.17%—Samsung Android16/3/202317/6/2026
Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.
ModificadaBaja (3.3)0.15%—Samsung Android16/3/202317/6/2026
Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
ModificadaMedia (5.5)0.17%—Samsung Android16/3/202317/6/2026
Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.
ModificadaCrítica (9.8)0.93%—Samsung Exynos 1280 FirmwareSamsung Exynos 2200 FirmwareSamsung Exynos Modem 5123 FirmwareSamsung Exynos Modem 5300 Firmware+113/3/202317/6/2026
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G SM message codec can occur due to insufficient parameter validation when decoding reserved options.
ModificadaCrítica (9.8)1.1%—Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+513/3/202317/6/2026
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when…
ModificadaCrítica (9.8)1.0%—Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+513/3/202317/6/2026
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123.. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when…
ModificadaCrítica (9.8)1.1%—Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+513/3/202317/6/2026
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when…
ModificadaCrítica (9.8)33%—Samsung Exynos Modem 5300 FirmwareSamsung Exynos Modem 5123 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 Firmware+113/3/202317/6/2026
The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.
ModificadaCrítica (9.8)0.95%—Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+510/3/202317/6/2026
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G MM message codec can occur due to insufficient parameter validation when…
ModificadaAlta (7.5)0.46%—Sunellsecurity Sn-xvr3804e1 FirmwareSunellsecurity Sn-xvr3808e2 FirmwareSunellsecurity Sn-adr3804e1 FirmwareSunellsecurity Sn-adr3808e1 Firmware+315/2/202317/6/2026
Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request.
ModificadaMedia (6.5)0.53%—Sunellsecurity Sn-xvr3804e1 FirmwareSunellsecurity Sn-xvr3808e2 FirmwareSunellsecurity Sn-adr3804e1 FirmwareSunellsecurity Sn-adr3808e1 Firmware+315/2/202317/6/2026
Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified request.
ModificadaCrítica (9.8)57%💥 ExploitSunlogin Sunflower13/2/202317/6/2026
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../ followed by the pathname of the…