Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
3672 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.41% | — | Samsung Escargot | 28/5/2026 | 17/6/2026 | Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31. | |
| Aplazada | Media (6.3) | 0.26% | — | Sunshinephotocart Sunshine Photo CartAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7. | |
| Analizada | Crítica (9.8) | 0.43% | — | Lizardbyte Sunshine | 22/5/2026 | 23/7/2026 | Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY,… | |
| Analizada | Alta (7.5) | 0.27% | — | Samsung Escargot | 19/5/2026 | 24/7/2026 | Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | |
| Analizada | Alta (7.5) | 0.27% | — | Samsung Escargot | 19/5/2026 | 24/7/2026 | Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | |
| Analizada | Alta (7.5) | 0.27% | — | Samsung Escargot | 19/5/2026 | 24/7/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | |
| Analizada | Crítica (9.8) | 0.32% | — | Samsung Escargot | 19/5/2026 | 24/7/2026 | Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | |
| Analizada | Alta (7.5) | 0.27% | — | Samsung Escargot | 19/5/2026 | 24/7/2026 | Memory allocation with excessive size value vulnerability in Samsung Open Source Escargot allows Excessive Allocation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | |
| Analizada | Alta (7.5) | 0.27% | — | Samsung Escargot | 19/5/2026 | 24/7/2026 | Release of invalid pointer or reference vulnerability in Samsung Open Source Escargot allows Buffer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | |
| Analizada | Crítica (9.8) | 0.32% | — | Samsung Escargot | 19/5/2026 | 24/7/2026 | Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | |
| Analizada | Crítica (9.8) | 0.32% | — | Samsung Escargot | 19/5/2026 | 24/7/2026 | Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | |
| Analizada | Alta (7.5) | 0.27% | — | Samsung Escargot | 19/5/2026 | 24/7/2026 | Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Data Payloads. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | |
| Analizada | Alta (7.5) | 0.27% | — | Samsung Walrus | 19/5/2026 | 24/7/2026 | NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation. This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9. | |
| Analizada | Alta (7.5) | 0.25% | — | Samsung Walrus | 19/5/2026 | 24/7/2026 | NULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via a crafted WebAssembly module containing deeply nested instructions. This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9. | |
| Pendiente de análisis | Media (6.3) | 0.09% | — | Samsung System Support ServiceAI | 13/5/2026 | 17/6/2026 | Improper privilege management in Samsung System Support Service prior to version 8.0.8.0 allows local attackers to trigger privileged functions. | |
| Analizada | Media (6.9) | 0.09% | — | Samsung Android | 13/5/2026 | 17/6/2026 | Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information. | |
| Analizada | Media (5.1) | 0.21% | — | Samsung Android | 13/5/2026 | 17/6/2026 | Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity. | |
| Analizada | Media (5.1) | 0.09% | 💥 PoC | Samsung Android | 13/5/2026 | 17/6/2026 | Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions. | |
| Pendiente de análisis | Alta (8.6) | 0.16% | 💥 PoC | Samsung Galaxy WatchAI | 13/5/2026 | 17/6/2026 | Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to execute arbitrary code with system privilege. | |
| Analizada | Media (6.8) | 0.15% | 💥 PoC | Samsung Android | 13/5/2026 | 17/6/2026 | Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code. | |
| Analizada | Media (5.1) | 0.09% | 💥 PoC | Samsung Android | 13/5/2026 | 17/6/2026 | Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information. | |
| Analizada | Media (6.8) | 0.09% | 💥 PoC | Samsung Android | 13/5/2026 | 17/6/2026 | Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier. | |
| Aplazada | Crítica (9.2) | 0.23% | — | Ingecon SUN EMS BoardAI | 12/5/2026 | 17/6/2026 | Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Board. The vulnerability arose because the secret access credentials were not based on a secure cryptographic scheme, but rather on a weak hashing algorithm, which could allow an attacker to carry out a… | |
| Analizada | Media (6.9) | 0.14% | — | HP Samsung Print Service Plugin | 6/5/2026 | 17/6/2026 | Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities. | |
| Aplazada | Alta (7.5) | 0.34% | — | Samsung Mobile Processor Exynos 980AISamsung Mobile Processor Exynos 990AISamsung Mobile Processor Exynos 850AISamsung Mobile Processor Exynos 2100AI+12 | 5/5/2026 | 17/6/2026 | An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, W920, W930, W1000, Modem 5123, and Modem 5300. Incorrect handling of 5G NR NAS registration accept messages leads to a Denial of Service. |