Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1690 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.09% | 💥 PoC | Samsung Android | 13/5/2026 | 17/6/2026 | Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions. | |
| Pendiente de análisis | Alta (8.6) | 0.16% | 💥 PoC | Samsung Galaxy WatchAI | 13/5/2026 | 17/6/2026 | Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to execute arbitrary code with system privilege. | |
| Analizada | Media (6.8) | 0.15% | 💥 PoC | Samsung Android | 13/5/2026 | 17/6/2026 | Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code. | |
| Analizada | Media (5.1) | 0.09% | 💥 PoC | Samsung Android | 13/5/2026 | 17/6/2026 | Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information. | |
| Analizada | Media (6.8) | 0.09% | 💥 PoC | Samsung Android | 13/5/2026 | 17/6/2026 | Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier. | |
| Analizada | Media (6.9) | 0.14% | — | HP Samsung Print Service Plugin | 6/5/2026 | 17/6/2026 | Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities. | |
| Aplazada | Alta (7.5) | 0.34% | — | Samsung Mobile Processor Exynos 980AISamsung Mobile Processor Exynos 990AISamsung Mobile Processor Exynos 850AISamsung Mobile Processor Exynos 2100AI+12 | 5/5/2026 | 17/6/2026 | An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, W920, W930, W1000, Modem 5123, and Modem 5300. Incorrect handling of 5G NR NAS registration accept messages leads to a Denial of Service. | |
| Analizada | Media (6.9) | 0.10% | — | Samsung Android | 29/4/2026 | 17/6/2026 | Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source ONE Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagation. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.1) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large intermediate tensors. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and memory corruption for oversized tensors. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in Samsung Open Source ONE. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (5.3) | 0.12% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large tensors in Samsung Open Source ONE. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (5.5) | 0.15% | — | Samsung ONE | 22/4/2026 | 24/9/2026 | Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0. | |
| Analizada | Alta (7.5) | 0.29% | — | Samsung Escargot | 13/4/2026 | 17/6/2026 | Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335. | |
| Analizada | Media (5.1) | 0.08% | 💥 PoC | Samsung Camera | 13/4/2026 | 17/6/2026 | Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (6.9) | 0.09% | 💥 PoC | Samsung Galaxy Wearable | 13/4/2026 | 17/6/2026 | Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information. | |
| Analizada | Media (6.8) | 0.09% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege. | |
| Analizada | Media (5.4) | 0.15% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock. | |
| Analizada | Alta (7.8) | 0.10% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions. | |
| Analizada | Media (4.1) | 0.23% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning. | |
| Analizada | Media (5.1) | 0.16% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information. |