Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
3672 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.12% | — | Samsung EscargotAI | 30/6/2026 | 30/6/2026 | Time-of-check time-of-use (TOCTOU) race condition vulnerability in Samsung Open Source Escargot allows Leveraging Race Conditions. This issue affects Escargot: bab3a5797557014ce3c2e28419a6310cfba90d0d. | |
| Aplazada | Baja (2.1) | 0.50% | — | Kortix-ai SunaAI | 21/6/2026 | 23/6/2026 | A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/src/app/auth/page.tsx of the component Auth Endpoint. Executing a manipulation of the argument returnURL can lead to cross site scripting. The attack may be… | |
| Analizada | Alta (7.5) | 0.64% | — | Sunnyadn Js-toml | 19/6/2026 | 26/6/2026 | js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 parse hexadecimal / octal / binary integer literals via a hand-written `parseBigInt` loop that multiplies a `BigInt` accumulator by the radix once per input digit. Each iteration performs a `BigInt *… | |
| Analizada | Media (5.9) | 0.10% | — | Samsung Android USB Driver | 5/6/2026 | 30/6/2026 | Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory. | |
| Analizada | Media (6.9) | 0.10% | — | Samsung Members | 5/6/2026 | 30/6/2026 | Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege. | |
| Analizada | Media (6.3) | 0.09% | — | Samsung Internet | 5/6/2026 | 30/6/2026 | Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information. | |
| Analizada | Media (6.5) | 0.30% | — | Samsung Plus TV | 5/6/2026 | 30/6/2026 | Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information. | |
| Analizada | Media (4.8) | 0.08% | — | Samsung Auto | 5/6/2026 | 30/6/2026 | Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration. | |
| Analizada | Media (6.9) | 0.09% | — | Samsung Assistant | 5/6/2026 | 17/6/2026 | Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | |
| Analizada | Media (6.9) | 0.09% | — | Samsung Assistant | 5/6/2026 | 17/6/2026 | Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | |
| Analizada | Media (5.2) | 0.09% | — | Samsung Android | 5/6/2026 | 17/6/2026 | Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (6.4) | 0.09% | — | Samsung Android | 5/6/2026 | 17/6/2026 | Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions. | |
| Analizada | Media (6.8) | 0.09% | — | Samsung Android | 5/6/2026 | 17/6/2026 | Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations. | |
| Analizada | Media (5.1) | 0.09% | — | Samsung Android | 5/6/2026 | 17/6/2026 | Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information. | |
| Analizada | Media (4.8) | 0.08% | — | Samsung Android | 5/6/2026 | 17/6/2026 | Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function. | |
| Analizada | Media (6.4) | 0.09% | — | Samsung Android | 5/6/2026 | 17/6/2026 | Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information. | |
| Analizada | Media (6.9) | 0.09% | — | Samsung Android | 5/6/2026 | 17/6/2026 | Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information. | |
| Analizada | Media (4.6) | 0.09% | 💥 PoC | Samsung Android | 5/6/2026 | 17/6/2026 | Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files. | |
| Aplazada | Media (6.1) | 0.15% | — | Samsung RlottieAI | 4/6/2026 | 22/7/2026 | Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd760aec00ada6a148635. | |
| Aplazada | Media (6.1) | 0.15% | — | Samsung RlottieAI | 4/6/2026 | 22/7/2026 | Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f. | |
| Aplazada | Media (6.1) | 0.15% | — | Samsung RlottieAI | 4/6/2026 | 22/7/2026 | Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3. | |
| Aplazada | Media (6.1) | 0.15% | — | Samsung RlottieAI | 4/6/2026 | 22/7/2026 | Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd. | |
| Aplazada | Media (6.1) | 0.15% | — | Samsung RlottieAI | 4/6/2026 | 22/7/2026 | Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035. | |
| Aplazada | Media (6.1) | 0.15% | — | Samsung RlottieAI | 4/6/2026 | 22/7/2026 | Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945. | |
| Aplazada | Media (6.1) | 0.10% | — | Samsung RlottieAI | 4/6/2026 | 22/7/2026 | Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd. |