Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.13% | — | Samsung SmartthingsAI | 10/8/2026 | 18/8/2026 | Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. | |
| Aplazada | Media (5.1) | 0.15% | — | Samsung SmartthingskitAI | 10/7/2026 | 10/7/2026 | Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. | |
| Analizada | Alta (8.8) | 0.76% | — | Samsung Smartthings | 11/3/2025 | 17/6/2026 | Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Samsung SmartThings. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Media (5.5) | 0.13% | — | Samsung Smartthings | 3/12/2024 | 17/6/2026 | Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information. | |
| Modificada | Alta (7.5) | 0.48% | — | Samsung Smartthings | 2/7/2024 | 17/6/2026 | Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner. | |
| Analizada | Baja (3.3) | 0.14% | — | Samsung Smartthings | 2/4/2024 | 17/6/2026 | Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to access testing configuration. | |
| Modificada | Alta (7.5) | 0.37% | — | Samsung Smartthings | 7/10/2022 | 17/6/2026 | Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts. | |
| Modificada | Alta (7.5) | 0.37% | — | Samsung Smartthings | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast. | |
| Modificada | Alta (7.5) | 0.37% | — | Samsung Smartthings | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast. | |
| Modificada | Alta (7.5) | 0.37% | — | Samsung Smartthings | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. | |
| Modificada | Alta (7.5) | 0.37% | — | Samsung Smartthings | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast. | |
| Modificada | Alta (7.5) | 0.37% | — | Samsung Smartthings | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. | |
| Modificada | Alta (7.5) | 0.37% | — | Samsung Smartthings | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. | |
| Modificada | Alta (7.5) | 0.35% | — | Samsung Smartthings | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent. | |
| Modificada | Alta (7.8) | 0.18% | — | Samsung Smartthings | 7/6/2022 | 17/6/2026 | Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity. | |
| Modificada | Media (5.5) | 0.19% | — | Samsung Smartthings | 7/6/2022 | 17/6/2026 | PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent. | |
| Modificada | Alta (7.5) | 0.87% | — | Samsung Smartthings | 7/6/2022 | 17/6/2026 | Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API. | |
| Modificada | Crítica (9.8) | 0.83% | — | Samsung Smartthings | 5/11/2021 | 17/6/2026 | Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation. | |
| Modificada | Media (5.3) | 0.79% | — | Samsung Smartthings Firmware | 5/8/2021 | 17/6/2026 | Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview. | |
| Modificada | Media (5.3) | 0.81% | — | Samsung Smartthings Firmware | 5/8/2021 | 17/6/2026 | Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview. | |
| Modificada | Baja (3.3) | 0.24% | — | Samsung Smartthings Firmware | 11/6/2021 | 17/6/2026 | Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log. | |
| Modificada | Media (5.3) | 0.97% | — | Samsung Smartthings | 9/4/2021 | 17/6/2026 | Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service. |