Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3672 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.83% | — | Sun.net Ehrd CpasSun.net Ehrd Ctms | 2/5/2026 | 17/6/2026 | CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analizada | Alta (8.7) | 0.55% | — | Sun.net Ehrd Ctms | 2/5/2026 | 17/6/2026 | CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Media (5.5) | 2.1% | — | Sunwood AI Labs Command Executor MCP ServerAI | 1/5/2026 | 17/6/2026 | A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of the file src/index.ts of the component MCP Interface. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Media (6.9) | 0.10% | — | Samsung Android | 29/4/2026 | 17/6/2026 | Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source ONE Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagation. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.1) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large intermediate tensors. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and memory corruption for oversized tensors. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (6.6) | 0.14% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in Samsung Open Source ONE. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (5.3) | 0.12% | — | Samsung ONE | 22/4/2026 | 17/6/2026 | Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large tensors in Samsung Open Source ONE. Affected version is prior to commit 1.30.0. | |
| Analizada | Media (5.5) | 0.15% | — | Samsung ONE | 22/4/2026 | 24/9/2026 | Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0. | |
| Analizada | Alta (7.5) | 0.29% | — | Samsung Escargot | 13/4/2026 | 17/6/2026 | Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335. | |
| Analizada | Media (5.1) | 0.08% | 💥 PoC | Samsung Camera | 13/4/2026 | 17/6/2026 | Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (6.9) | 0.09% | 💥 PoC | Samsung Galaxy Wearable | 13/4/2026 | 17/6/2026 | Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information. | |
| Analizada | Media (6.8) | 0.09% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege. | |
| Analizada | Media (5.4) | 0.15% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock. | |
| Analizada | Alta (7.8) | 0.10% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions. | |
| Analizada | Media (4.1) | 0.23% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning. | |
| Analizada | Media (5.1) | 0.16% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information. | |
| Analizada | Media (4.4) | 0.16% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard. | |
| Analizada | Media (4.7) | 0.13% | 💥 PoC | Samsung Android | 13/4/2026 | 17/6/2026 | Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents. | |
| Analizada | Crítica (9.8) | 0.29% | — | Samsung Escargot | 13/4/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335. | |
| Analizada | Crítica (9.1) | 0.25% | — | Samsung Escargot | 13/4/2026 | 17/6/2026 | Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335. |