Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.8)0.18%—Samsung Magicinfo 9 ServerAI10/4/202617/6/2026
Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 21.1091.1.
AnalizadaCrítica (9.8)0.48%—Samsung Magicinfo 9 Server2/2/202617/6/2026
The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1.
AnalizadaAlta (8.8)0.45%—Samsung Magicinfo 9 Server2/2/202617/6/2026
An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1.
AnalizadaCrítica (9.8)0.55%—Samsung Magicinfo 9 Server2/2/202617/6/2026
A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1.
AnalizadaCrítica (9.8)0.55%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.54%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)24%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.39%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.65%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.59%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.63%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.60%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.46%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.61%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0
AnalizadaCrítica (9.8)12%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.60%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.57%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0
AnalizadaCrítica (9.8)0.47%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaAlta (8.8)10%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.50%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaAlta (8.8)9.0%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
AnalizadaCrítica (9.8)0.61%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0
AnalizadaCrítica (9.8)24%⚠ Explotación activaSamsung Magicinfo 9 Server13/5/202517/6/2026
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
AnalizadaCrítica (9.8)92%⚠ Explotación activaSamsung Magicinfo 9 Server12/8/20241/10/2026
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.