Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.07% | — | Samsung Galaxy Store | 16/3/2026 | 17/6/2026 | Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application. | |
| Analizada | Media (5.9) | 0.12% | — | Samsung Galaxy Store | 16/3/2026 | 17/6/2026 | Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege. | |
| Analizada | Alta (7) | 0.13% | — | Samsung Galaxy Store | 16/3/2026 | 17/6/2026 | Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege. | |
| Analizada | Media (5.1) | 0.16% | — | Samsung Galaxy Store | 9/1/2026 | 17/6/2026 | Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script. | |
| Analizada | Baja (3.3) | 0.10% | — | Samsung Galaxy Store | 2/12/2025 | 25/9/2026 | Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store. | |
| Analizada | Media (5.5) | 0.10% | — | Samsung Galaxy Store | 3/9/2025 | 17/6/2026 | Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service. | |
| Analizada | Media (5.5) | 0.14% | — | Samsung Galaxy Store | 8/4/2025 | 17/6/2026 | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store. | |
| Analizada | Media (4.6) | 0.20% | — | Samsung Galaxy Store | 4/2/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard. | |
| Analizada | Media (5.3) | 0.13% | — | Samsung Galaxy Store | 2/7/2024 | 17/6/2026 | Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore. | |
| Analizada | Media (5.5) | 0.14% | — | Samsung Galaxy Store | 7/5/2024 | 17/6/2026 | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Galaxy Store | 6/2/2024 | 17/6/2026 | Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Galaxy Store | 6/2/2024 | 17/6/2026 | Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Galaxy Store | 6/2/2024 | 17/6/2026 | Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Galaxy Store | 6/2/2024 | 17/6/2026 | Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. | |
| Modificada | Alta (7.5) | 1.2% | — | Samsung Galaxy Store | 5/12/2023 | 17/6/2026 | Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data. | |
| Modificada | Crítica (9.8) | 0.97% | — | Samsung Galaxy Store | 5/12/2023 | 17/6/2026 | Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store. | |
| Modificada | Media (5.5) | 0.15% | — | Samsung Galaxy Store | 10/8/2023 | 17/6/2026 | Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission. | |
| Modificada | Crítica (9.6) | 0.55% | — | Samsung Galaxy Store | 26/5/2023 | 17/6/2026 | XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. | |
| Modificada | Alta (8.8) | 0.52% | — | Samsung Galaxy Store | 26/5/2023 | 17/6/2026 | InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. | |
| Modificada | Alta (8.8) | 0.52% | — | Samsung Galaxy Store | 26/5/2023 | 17/6/2026 | Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. | |
| Modificada | Media (6.1) | 13% | — | Samsung Galaxy Store | 9/2/2023 | 17/6/2026 | Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page. | |
| Modificada | Alta (7.8) | 3.7% | — | Samsung Galaxy Store | 9/2/2023 | 17/6/2026 | Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store. | |
| Modificada | Alta (7.8) | 0.21% | — | Samsung Galaxy Store | 12/7/2022 | 17/6/2026 | Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege. | |
| Modificada | Alta (7.8) | 0.21% | — | Samsung Galaxy Store | 12/7/2022 | 17/6/2026 | Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege. | |
| Modificada | Alta (7.8) | 0.21% | — | Samsung Galaxy Store | 12/7/2022 | 17/6/2026 | Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege. |