Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.52% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 FirmwareSamsung Galaxy S4 Mini FirmwareSamsung Galaxy S4 Mini LTE Firmware+1 | 13/4/2017 | 17/6/2026 | Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices allow attackers to send AT commands by plugging the device into a Linux… | |
| Modificada | Media (6.8) | 0.51% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 FirmwareSamsung Galaxy S4 Mini FirmwareSamsung Galaxy S4 Mini LTE Firmware+1 | 13/4/2017 | 17/6/2026 | Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2… | |
| Modificada | Baja (3.3) | 0.40% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 Firmware | 13/4/2017 | 17/6/2026 | secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by the… | |
| Modificada | Crítica (9.8) | 1.5% | — | Samsung Galaxy S6 Firmware | 13/4/2017 | 17/6/2026 | Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081. | |
| Modificada | Baja (3.3) | 0.42% | — | Samsung Galaxy S6 Firmware | 13/4/2017 | 17/6/2026 | Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to read sent e-mail messages, aka SVE-2015-5081. | |
| Modificada | Media (5.5) | 0.36% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 Firmware | 13/4/2017 | 17/6/2026 | The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to trigger a NULL pointer dereference via a "GET HTTP/1.1" request, aka SVE-2016-5036. | |
| Modificada | Alta (8.8) | 7.4% | 💥 Exploit | Samsung Galaxy S6 | 11/4/2017 | 17/6/2026 | SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript. | |
| Modificada | Alta (8) | 0.81% | — | Samsung Galaxy APPSamsung Account APP | 27/3/2017 | 17/6/2026 | Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code. | |
| Modificada | Alta (8) | 0.68% | — | Samsung Galaxy APPSamsung Account APP | 27/3/2017 | 17/6/2026 | GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Samsung Galaxy S6 | 16/11/2015 | 17/6/2026 | The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image file. | |
| Modificada | Alta (7.9) | 1.2% | — | Samsung Galaxy S5 | 6/7/2015 | 17/6/2026 | The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitrary files via a crafted Parcelable object in a serialized MethodSpec object. | |
| Modificada | Media (5.4) | 0.27% | — | IGG Galaxy Online 2 | 24/9/2014 | 17/6/2026 | The Galaxy Online 2 (aka air.com.igg.galaxyAPhone) application 1.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Permadi Mahjong Galaxy Space Lite | 9/9/2014 | 17/6/2026 | The Mahjong Galaxy Space Lite (aka air.com.permadi.mahjongIris) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 15% | 💥 PoC | Meizu MXSamsung Galaxy Note 2Samsung Galaxy S2 | 18/12/2012 | 16/6/2026 | The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to read or write arbitrary physical memory and gain privileges via a crafted application, as demonstrated… | |
| Modificada | Alta (7.1) | 1.8% | — | ATT StatusHTC ChachaHTC DesireHTC Merge+5 | 21/8/2012 | 16/6/2026 | The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain… | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Galaxyscriptz Myphpauction | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Redgalaxy Download Center | 1/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the default URI in Chris LaPointe RedGalaxy Download Center 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter, (2) message parameter in a login action, (3) category parameter in a browse action, (4) now parameter, or (5)… | |
| Modificada | Media (6.8) | 3.1% | 💥 Exploit | Galaxyscripts Mini File Host | 1/5/2009 | 16/6/2026 | Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as demonstrated by creating a name.php file. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Galaxyscripts Mini File Host | 18/1/2008 | 16/6/2026 | Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Audiogalaxy | 31/12/2001 | 16/6/2026 | Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack. |