Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.18% | — | Samsung Magicinfo 9 ServerAI | 10/4/2026 | 17/6/2026 | Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 21.1091.1. | |
| Analizada | Crítica (9.8) | 0.48% | — | Samsung Magicinfo 9 Server | 2/2/2026 | 17/6/2026 | The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1. | |
| Analizada | Alta (8.8) | 0.45% | — | Samsung Magicinfo 9 Server | 2/2/2026 | 17/6/2026 | An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1. | |
| Analizada | Crítica (9.8) | 0.55% | — | Samsung Magicinfo 9 Server | 2/2/2026 | 17/6/2026 | A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1. | |
| Analizada | Crítica (9.8) | 0.55% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.54% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 24% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.39% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.65% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.59% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.63% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.60% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.46% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.61% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0 | |
| Analizada | Crítica (9.8) | 12% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.60% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.57% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0 | |
| Analizada | Crítica (9.8) | 0.47% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Alta (8.8) | 10% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.50% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Alta (8.8) | 9.0% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.61% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0 | |
| Analizada | Crítica (9.8) | 24% | ⚠ Explotación activa | Samsung Magicinfo 9 Server | 13/5/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority. | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa | Samsung Magicinfo 9 Server | 12/8/2024 | 1/10/2026 | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority. |