Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1338▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.53% | — | Gladysassistant Gladys AssistantAI | 21/9/2026 | 23/9/2026 | Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a… | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Modificada | Media (6.5) | 1.0% | — | Gladysassistant Gladys Assistant | 7/12/2023 | 17/6/2026 | Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine. | |
| Modificada | Baja (3.3) | 0.13% | — | Samsung Sassistant | 4/10/2023 | 17/6/2026 | Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access backup data in SAssistant. | |
| Modificada | Media (6.5) | 0.84% | — | Gladysassistant Gladys Assistant | 25/9/2023 | 17/6/2026 | A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input. |