Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▲ 32 respecto a la semana anterior
Críticas / altas1474▲ 364 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
–

195 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.4)0.37%—Galaxy NGAIPulpAI25/8/202628/8/2026
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, including internal networks, loopback, or cloud instance metadata endpoints. A…
Pendiente de análisisMedia (5.3)0.49%—MY GalaxyAI10/8/202618/8/2026
Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
Pendiente de análisisAlta (7.5)0.89%—Galaxy NGAI16/6/202629/6/2026
A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. An authenticated user who controls a git repository can create a…
Pendiente de análisisAlta (8.6)0.16%—Samsung Galaxy WatchAI13/5/202617/6/2026
Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to execute arbitrary code with system privilege.
AnalizadaMedia (6.9)0.09%—Samsung Galaxy Wearable13/4/202617/6/2026
Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information.
AnalizadaMedia (5.9)0.07%—Samsung Galaxy Store16/3/202617/6/2026
Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.
AnalizadaMedia (5.9)0.12%—Samsung Galaxy Store16/3/202617/6/2026
Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
AnalizadaAlta (7)0.13%—Samsung Galaxy Store16/3/202617/6/2026
Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
AplazadaAlta (7.1)0.24%—Galaxy Forces MmorpgAI6/3/202617/6/2026
Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'type' parameter. Attackers can send POST requests to ads.php with crafted SQL payloads in the type parameter to extract sensitive database…
AplazadaCrítica (9.1)0.30%—Xiaomi Galaxy FDS SDK AndroidAIApache HttpclientAI12/2/202614/7/2026
Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid…
AplazadaAlta (8.7)0.15%—GalaxydiagnosticsAI4/2/202617/6/2026
Improper input validation in GalaxyDiagnostics prior to version 3.5.050 allows local privileged attackers to execute privileged commands.
AplazadaMedia (5.1)0.16%—Samsung Galaxy WearableAI4/2/202617/6/2026
Improper handling of insufficient permission in Galaxy Wearable installed on non-Samsung Device prior to version 2.2.68 allows local attackers to access sensitive information.
AnalizadaMedia (5.1)0.16%—Samsung Galaxy Store9/1/202617/6/2026
Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.
AnalizadaBaja (3.3)0.10%—Samsung Galaxy Store2/12/202525/9/2026
Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store.
AnalizadaMedia (6.8)0.12%—Cdprojekt GOG Galaxy5/11/202517/6/2026
GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update requests and replace installer or update packages with malicious files.
AplazadaCrítica (9.3)0.49%—Galaxy Software Services Corporation Vitals ESP Forum ModuleAI20/10/202530/9/2026
An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file.
AplazadaMedia (4.3)0.14%—Galaxyweblinks Post Featured VideoAI26/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Post Featured Video post-featured-video allows Cross Site Request Forgery.This issue affects Post Featured Video: from n/a through <= 1.7.
AnalizadaMedia (5.5)0.10%—Samsung Galaxy Store3/9/202517/6/2026
Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.
AplazadaBaja (3.3)0.12%—Samsung Galaxy WatchAIGoogle Android WatchAI6/8/202517/6/2026
Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information.
AnalizadaMedia (5.5)0.12%—Samsung Galaxy Wearable6/8/202517/6/2026
Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.
AplazadaMedia (6.2)0.14%—Samsung Galaxy WatchAI6/8/202517/6/2026
Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time.
AplazadaMedia (5.5)0.12%—Samsung Galaxy WatchAI6/8/202517/6/2026
Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration.
AplazadaMedia (5.5)0.13%—Samsung Galaxy WatchAI6/8/202517/6/2026
Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to motion and body sensors.
AplazadaMedia (5.3)0.51%—Kingdee Cloud Galaxy Private Cloud BBC SystemAI21/5/202517/6/2026
A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classified as critical. Affected by this vulnerability is the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file fileUpload/deleteFileAction.jhtml of the component File Handler. The…
AplazadaAlta (8.1)0.24%—Samsung Galaxy BudsAISamsung Galaxy Buds 2AI14/5/202517/6/2026
Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequence, audio playback takeover or even microphone recording without user consent or notification is achieved. Note: This is considered a low severity vulnerability by the…