Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
3672 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.44% | — | Silabs Wi-sun Software Development KIT | 21/3/2023 | 17/6/2026 | Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network. | |
| Modificada | Media (5.5) | 0.19% | — | Samsung Bixbytouch | 16/3/2023 | 17/6/2026 | Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files. | |
| Modificada | Baja (3.3) | 0.14% | — | Samsung Calendar | 16/3/2023 | 17/6/2026 | Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status. | |
| Modificada | Baja (3.3) | 0.15% | — | Samsung Myfiles | 16/3/2023 | 17/6/2026 | Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific conditions. | |
| Modificada | Baja (3.3) | 0.16% | — | Samsung Quick Share | 16/3/2023 | 17/6/2026 | The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission. | |
| Modificada | Media (5.5) | 0.15% | — | Samsung Android | 16/3/2023 | 17/6/2026 | Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity. | |
| Modificada | Media (4.4) | 0.16% | — | Samsung Android | 16/3/2023 | 17/6/2026 | Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting. | |
| Modificada | Crítica (9.8) | 0.27% | — | Samsung Android | 16/3/2023 | 17/6/2026 | Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault. | |
| Modificada | Baja (3.3) | 0.15% | — | Samsung Android | 16/3/2023 | 17/6/2026 | Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent. | |
| Modificada | Alta (8.1) | 0.17% | — | Samsung Android | 16/3/2023 | 17/6/2026 | Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission. | |
| Modificada | Media (5.5) | 0.22% | — | Samsung Android | 16/3/2023 | 17/6/2026 | Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid. | |
| Modificada | Crítica (9.1) | 0.40% | — | Samsung Exynos Firmware | 16/3/2023 | 17/6/2026 | Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message. | |
| Modificada | Baja (2.4) | 0.23% | — | Samsung Android | 16/3/2023 | 17/6/2026 | Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Android | 16/3/2023 | 17/6/2026 | Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data. | |
| Modificada | Baja (3.3) | 0.15% | — | Samsung Android | 16/3/2023 | 17/6/2026 | Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Android | 16/3/2023 | 17/6/2026 | Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission. | |
| Modificada | Crítica (9.8) | 0.93% | — | Samsung Exynos 1280 FirmwareSamsung Exynos 2200 FirmwareSamsung Exynos Modem 5123 FirmwareSamsung Exynos Modem 5300 Firmware+1 | 13/3/2023 | 17/6/2026 | An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G SM message codec can occur due to insufficient parameter validation when decoding reserved options. | |
| Modificada | Crítica (9.8) | 1.1% | — | Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+5 | 13/3/2023 | 17/6/2026 | An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when… | |
| Modificada | Crítica (9.8) | 1.0% | — | Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+5 | 13/3/2023 | 17/6/2026 | An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123.. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when… | |
| Modificada | Crítica (9.8) | 1.1% | — | Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+5 | 13/3/2023 | 17/6/2026 | An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when… | |
| Modificada | Crítica (9.8) | 33% | — | Samsung Exynos Modem 5300 FirmwareSamsung Exynos Modem 5123 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 Firmware+1 | 13/3/2023 | 17/6/2026 | The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service. | |
| Modificada | Crítica (9.8) | 0.95% | — | Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+5 | 10/3/2023 | 17/6/2026 | An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G MM message codec can occur due to insufficient parameter validation when… | |
| Modificada | Alta (7.5) | 0.46% | — | Sunellsecurity Sn-xvr3804e1 FirmwareSunellsecurity Sn-xvr3808e2 FirmwareSunellsecurity Sn-adr3804e1 FirmwareSunellsecurity Sn-adr3808e1 Firmware+3 | 15/2/2023 | 17/6/2026 | Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request. | |
| Modificada | Media (6.5) | 0.53% | — | Sunellsecurity Sn-xvr3804e1 FirmwareSunellsecurity Sn-xvr3808e2 FirmwareSunellsecurity Sn-adr3804e1 FirmwareSunellsecurity Sn-adr3808e1 Firmware+3 | 15/2/2023 | 17/6/2026 | Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified request. | |
| Modificada | Crítica (9.8) | 57% | 💥 Exploit | Sunlogin Sunflower | 13/2/2023 | 17/6/2026 | Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../ followed by the pathname of the… |