Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
–

3668 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.28%—Gedelumbung HospitalmanagementAISunhater KcfinderAI30/9/202630/9/2026
A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the…
Pendiente de análisisCrítica (10)0.39%—SuneditorAI23/9/202624/9/2026
SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders…
AplazadaMedia (5.3)0.36%—Sunnyadn Js-tomlAI22/9/202626/9/2026
js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does not bound nesting or dotted-key depth in the recursive parser at src/load/parser.ts or the interpreter at src/load/interpreter.ts, so deeply nested arrays, deeply nested inline tables, or long dotted keys can exhaust the V8 call stack and throw a raw…
AplazadaMedia (5.5)0.14%—Samsung EscargotAI15/9/202618/9/2026
Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This issue affects Escargot: ac94df78493ee6fede286620d94f724e46b4d238.
AplazadaMedia (4.4)0.14%—Samsung RlottieAI15/9/202618/9/2026
Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39.
Pendiente de análisisBaja (2.8)0.09%—Samsung Exynos 9810AISamsung Exynos 9610AISamsung Exynos 9820AISamsung Exynos 980AI+1214/9/202622/9/2026
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123.…
Pendiente de análisisBaja (3.5)0.32%—Samsung Exynos 850AISamsung Exynos 1080AISamsung Exynos 2100AISamsung Exynos 1280AI+1214/9/202622/9/2026
An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration…
Pendiente de análisisBaja (2.8)0.12%—Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI+414/9/202622/9/2026
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.
Pendiente de análisisBaja (2.8)0.12%—Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI+414/9/202622/9/2026
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption.
Pendiente de análisisBaja (2.8)0.13%—Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI+414/9/202622/9/2026
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code.
Pendiente de análisisMedia (6.4)0.13%—Samsung Exynos 1580AISamsung Exynos 2500AI14/9/202622/9/2026
An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.
Pendiente de análisisAlta (7.5)0.14%—Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI+414/9/202622/9/2026
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.
Pendiente de análisisBaja (2.8)0.13%—Samsung Exynos 850AISamsung Exynos 1280AISamsung Exynos 1330AISamsung Exynos 1380AI+414/9/202622/9/2026
An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.
Pendiente de análisisBaja (2.8)0.12%—Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 1580AI+414/9/202622/9/2026
An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and causing a denial of service (DoS).
Pendiente de análisisMedia (4.2)0.13%—Samsung Exynos 1580AISamsung Custos DriverAI14/9/202622/9/2026
An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage.
Pendiente de análisisBaja (2.8)0.12%—Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI+214/9/202622/9/2026
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service.
Pendiente de análisisBaja (3.5)0.20%—Samsung Exynos 1330AISamsung Exynos 1380AISamsung Exynos 1480AISamsung Exynos 2400AI14/9/202622/9/2026
An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vulnerability in the camera GDC driver may lead to kernel memory corruption under certain conditions.
Pendiente de análisisMedia (4)0.13%—Samsung Exynos 1080AISamsung Exynos 2100AISamsung Exynos 1280AISamsung Exynos 2200AI+1014/9/202622/9/2026
An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to crash.
Pendiente de análisisMedia (4.2)0.09%—Samsung Exynos 1280AISamsung Exynos 2200AISamsung Exynos 1380AISamsung Exynos 1480AI+514/9/202622/9/2026
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege…
Pendiente de análisisMedia (4.2)0.09%—Samsung Exynos 1280AISamsung Exynos 2200AISamsung Exynos 1380AISamsung Exynos 1480AI+514/9/202622/9/2026
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.
Pendiente de análisisAlta (7.8)0.11%—Samsung Exynos 850AISamsung Exynos 1080AISamsung Exynos 2100AISamsung Exynos 1280AI+1214/9/202622/9/2026
An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling)…
Pendiente de análisisMedia (4.2)0.10%—Samsung Exynos 1280AISamsung Exynos 2200AISamsung Exynos 1380AI14/9/202622/9/2026
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.
Pendiente de análisisMedia (4.2)0.09%—Samsung Exynos 1280AISamsung Exynos 2200AISamsung Exynos 1380AISamsung Exynos 1480AI+514/9/202622/9/2026
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash.
Pendiente de análisisBaja (2.8)0.08%—Samsung Exynos 1280AISamsung Exynos 2200AISamsung Exynos 1380AISamsung Exynos 1480AI+514/9/202622/9/2026
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A TOCTOU race condition in the Exynos DRM HDR Driver leads to a heap overflow, causing a kernel crash.
Pendiente de análisisMedia (5.7)0.16%—Samsung Automotive Processor Exynos Auto 8890AISamsung Automotive Processor Exynos Auto V7AISamsung Automotive Processor Exynos Auto V9AISamsung Automotive Processor Exynos Auto V920AI14/9/202628/9/2026
An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.