Vulnerabilities

Summary — last 7 days

New vulnerabilities2,731▼ 12 vs. last week
Critical / high1,272▼ 242 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
–

10 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedHigh (8.7)0.74%—Securecomputing Snapgear Sg560 Firmware1/6/20266/17/2026
SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files using the edit_config_files CGI script. Attackers can manipulate POST request parameters in /cgi-bin/cgix/edit_config_files to access and modify files outside the intended…
AnalyzedMedium (5.1)0.28%—Securecomputing Snapgear Sg560 Firmware1/6/20266/17/2026
SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft a malicious web page that automatically submits a form to create a new super user account with full administrative…
ModifiedHigh (8.8)0.44%—Samsung Galaxy Watch Active 2 FirmwareSamsung Galaxy Watch Active FirmwareSamsung Galaxy Watch FirmwareSamsung Galaxy Watch 3 Firmware+56/11/20216/17/2026
Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.
ModifiedMedium (6.5)0.40%—Samsung Gear S6/11/20216/17/2026
Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.
ModifiedCritical (9.8)1.6%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+61/22/20206/17/2026
The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
ModifiedMedium (6.5)0.81%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+61/22/20206/17/2026
The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based…
ModifiedHigh (7.5)1.2%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+61/22/20206/17/2026
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.
ModifiedHigh (7.5)1.4%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+61/22/20206/17/2026
The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
ModifiedMedium (4.7)0.40%💥 PoCGearsoftware Gearaspiwdm8/24/20186/17/2026
GEAR Software products that include GEARAspiWDM.sys, 2.2.5.0, allow local users to cause a denial of service (Race Condition and BSoD on Windows) by not checking that user-mode memory is available right before writing to it. A check is only performed at the beginning of a long subroutine.
ModifiedHigh (7.8)1.8%—Securecomputing Snapgear Sg560Securecomputing Snapgear Sg565Securecomputing Snapgear Sg580Securecomputing Snapgear Sg7109/7/20066/16/2026
Multiple unspecified vulnerabilities in SnapGear before 3.1.4u1 allow remote attackers to cause a denial of service via unspecified vectors involving (1) IPSec replay windows and (2) the use of vulnerable versions of ClamAV before 0.88.4. NOTE: it is possible that vector 2 is related to CVE-2006-4018.
Orbitaley — Vulnerabilities