Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
3668 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.28% | — | Gedelumbung HospitalmanagementAISunhater KcfinderAI | 30/9/2026 | 30/9/2026 | A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the… | |
| Pendiente de análisis | Crítica (10) | 0.39% | — | SuneditorAI | 23/9/2026 | 24/9/2026 | SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders… | |
| Aplazada | Media (5.3) | 0.36% | — | Sunnyadn Js-tomlAI | 22/9/2026 | 26/9/2026 | js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does not bound nesting or dotted-key depth in the recursive parser at src/load/parser.ts or the interpreter at src/load/interpreter.ts, so deeply nested arrays, deeply nested inline tables, or long dotted keys can exhaust the V8 call stack and throw a raw… | |
| Aplazada | Media (5.5) | 0.14% | — | Samsung EscargotAI | 15/9/2026 | 18/9/2026 | Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This issue affects Escargot: ac94df78493ee6fede286620d94f724e46b4d238. | |
| Aplazada | Media (4.4) | 0.14% | — | Samsung RlottieAI | 15/9/2026 | 18/9/2026 | Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39. | |
| Pendiente de análisis | Baja (2.8) | 0.09% | — | Samsung Exynos 9810AISamsung Exynos 9610AISamsung Exynos 9820AISamsung Exynos 980AI+12 | 14/9/2026 | 22/9/2026 | An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123.… | |
| Pendiente de análisis | Baja (3.5) | 0.32% | — | Samsung Exynos 850AISamsung Exynos 1080AISamsung Exynos 2100AISamsung Exynos 1280AI+12 | 14/9/2026 | 22/9/2026 | An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration… | |
| Pendiente de análisis | Baja (2.8) | 0.12% | — | Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI+4 | 14/9/2026 | 22/9/2026 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access. | |
| Pendiente de análisis | Baja (2.8) | 0.12% | — | Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI+4 | 14/9/2026 | 22/9/2026 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption. | |
| Pendiente de análisis | Baja (2.8) | 0.13% | — | Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI+4 | 14/9/2026 | 22/9/2026 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code. | |
| Pendiente de análisis | Media (6.4) | 0.13% | — | Samsung Exynos 1580AISamsung Exynos 2500AI | 14/9/2026 | 22/9/2026 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service. | |
| Pendiente de análisis | Alta (7.5) | 0.14% | — | Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI+4 | 14/9/2026 | 22/9/2026 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service. | |
| Pendiente de análisis | Baja (2.8) | 0.13% | — | Samsung Exynos 850AISamsung Exynos 1280AISamsung Exynos 1330AISamsung Exynos 1380AI+4 | 14/9/2026 | 22/9/2026 | An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage. | |
| Pendiente de análisis | Baja (2.8) | 0.12% | — | Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 1580AI+4 | 14/9/2026 | 22/9/2026 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and causing a denial of service (DoS). | |
| Pendiente de análisis | Media (4.2) | 0.13% | — | Samsung Exynos 1580AISamsung Custos DriverAI | 14/9/2026 | 22/9/2026 | An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage. | |
| Pendiente de análisis | Baja (2.8) | 0.12% | — | Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI+2 | 14/9/2026 | 22/9/2026 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service. | |
| Pendiente de análisis | Baja (3.5) | 0.20% | — | Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI | 14/9/2026 | 22/9/2026 | An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vulnerability in the camera GDC driver may lead to kernel memory corruption under certain conditions. | |
| Pendiente de análisis | Media (4) | 0.13% | — | Samsung Exynos 1080AISamsung Exynos 2100AISamsung Exynos 1280AISamsung Exynos 2200AI+10 | 14/9/2026 | 22/9/2026 | An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to crash. | |
| Pendiente de análisis | Media (4.2) | 0.09% | — | Samsung Exynos 1280AISamsung Exynos 2200AISamsung Exynos 1380AISamsung Exynos 1480AI+5 | 14/9/2026 | 22/9/2026 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege… | |
| Pendiente de análisis | Media (4.2) | 0.09% | — | Samsung Exynos 1280AISamsung Exynos 2200AISamsung Exynos 1380AISamsung Exynos 1480AI+5 | 14/9/2026 | 22/9/2026 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free. | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Samsung Exynos 850AISamsung Exynos 1080AISamsung Exynos 2100AISamsung Exynos 1280AI+12 | 14/9/2026 | 22/9/2026 | An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling)… | |
| Pendiente de análisis | Media (4.2) | 0.10% | — | Samsung Exynos 1280AISamsung Exynos 2200AISamsung Exynos 1380AI | 14/9/2026 | 22/9/2026 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash. | |
| Pendiente de análisis | Media (4.2) | 0.09% | — | Samsung Exynos 1280AISamsung Exynos 2200AISamsung Exynos 1380AISamsung Exynos 1480AI+5 | 14/9/2026 | 22/9/2026 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash. | |
| Pendiente de análisis | Baja (2.8) | 0.08% | — | Samsung Exynos 1280AISamsung Exynos 2200AISamsung Exynos 1380AISamsung Exynos 1480AI+5 | 14/9/2026 | 22/9/2026 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A TOCTOU race condition in the Exynos DRM HDR Driver leads to a heap overflow, causing a kernel crash. | |
| Pendiente de análisis | Media (5.7) | 0.16% | — | Samsung Automotive Processor Exynos Auto 8890AISamsung Automotive Processor Exynos Auto V7AISamsung Automotive Processor Exynos Auto V9AISamsung Automotive Processor Exynos Auto V920AI | 14/9/2026 | 28/9/2026 | An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel. |