Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.14% | — | Sktelecom Com.skt.prod.dialer | 21/7/2025 | 17/6/2026 | The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCallInternalBroadcaster component. | |
| Aplazada | Media (5.4) | 0.27% | — | WombatdialersAI | 18/2/2025 | 17/6/2026 | Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to system logs and could be used by a malicious attacker to impersonate an existing user session. | |
| Aplazada | Media (5) | 0.27% | — | Wombat DialerAI | 18/2/2025 | 17/6/2026 | Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is limited to services used by the client (not the general-use JSON services) and requires reverse engineering of the… | |
| Aplazada | Alta (7.5) | 0.32% | — | Samsung DialerAI | 7/11/2024 | 17/6/2026 | The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivity component. | |
| Modificada | Media (5.3) | 0.50% | — | Simplemobiletools Simple Dialer | 27/12/2023 | 17/6/2026 | An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interaction with com.simplemobiletools.dialer.activities.DialerActivity. | |
| Modificada | Alta (7.5) | 0.66% | — | Xenomtechnologies Phone Dialer-voice Call Dialer | 27/12/2023 | 17/6/2026 | An issue in Xenom Technologies (sinous) Phone Dialer-voice Call Dialer v.1.2.5 allows an attacker to bypass intended access restrictions via interaction with com.funprime.calldialer.ui.activities.OutgoingActivity. | |
| Modificada | Baja (3.3) | 0.32% | — | Fulldive Full Dialer | 13/9/2023 | 17/6/2026 | The com.full.dialer.top.secure.encrypted application through 1.0.1 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.full.dialer.top.secure.encrypted.activities.DialerActivity component. | |
| Modificada | Baja (3.3) | 0.22% | — | Samsung Dialer | 8/12/2021 | 17/6/2026 | Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID. | |
| Modificada | Alta (7.2) | 1.2% | — | Hp-uxAvaya Predictive Dialer System | 31/12/2003 | 16/6/2026 | Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument. | |
| Modificada | Media (5.5) | 0.13% | — | Tata Integrated Dialer | 31/12/2002 | 16/6/2026 | Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" option is used, stores the password with a weak encryption scheme (one-to-one mapping) in a registry key, which allows local users to obtain and decrypt the password. |