Total
29997 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-20956 | 1 Samsung | 11 Galaxy Watch, Galaxy Watch 4, Galaxy Watch 4 Classic and 8 more | 2026-06-17 | N/A | 4.3 MEDIUM |
| Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to access developer settings. | |||||
| CVE-2025-20955 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images. | |||||
| CVE-2025-20954 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | |||||
| CVE-2025-20951 | 1 Samsung | 1 Galaxy Store | 2026-06-17 | N/A | 5.1 MEDIUM |
| Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store. | |||||
| CVE-2025-20950 | 1 Samsung | 1 Notes | 2026-06-17 | N/A | 4.0 MEDIUM |
| Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information. | |||||
| CVE-2025-20947 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability. | |||||
| CVE-2025-20942 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.4 MEDIUM |
| Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID. | |||||
| CVE-2025-20926 | 2 Google, Samsung | 2 Android, Myfiles | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local attackers to access files with My Files' privilege. | |||||
| CVE-2025-20909 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.0 MEDIUM |
| Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information. | |||||
| CVE-2025-20896 | 1 Samsung | 1 Easysetup | 2026-06-17 | N/A | 4.0 MEDIUM |
| Use of implicit intent for sensitive communication in EasySetup prior to version 11.1.18 allows local attackers to access sensitive information. | |||||
| CVE-2025-20895 | 1 Samsung | 1 Galaxy Store | 2026-06-17 | N/A | 3.2 LOW |
| Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard. | |||||
| CVE-2025-20893 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.1 MEDIUM |
| Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications. | |||||
| CVE-2025-20884 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.6 MEDIUM |
| Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles. | |||||
| CVE-2025-20883 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.6 MEDIUM |
| Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles. | |||||
| CVE-2025-20664 | 1 Mediatek | 7 Mt7915, Mt7916, Mt7981 and 4 more | 2026-06-17 | N/A | 7.5 HIGH |
| In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406217; Issue ID: MSV-2773. | |||||
| CVE-2025-20615 | 1 Qardio | 1 Qardio | 2026-06-17 | N/A | 6.2 MEDIUM |
| The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the attacker to send hex-based commands over a UI-based terminal. | |||||
| CVE-2025-20383 | 1 Splunk | 3 Splunk, Splunk Cloud Platform, Splunk Secure Gateway | 2026-06-17 | N/A | 4.3 MEDIUM |
| In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscribes to mobile push notifications could receive notifications that disclose the title and description of the report or alert even if they do not have access to view the report or alert. | |||||
| CVE-2025-1934 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-06-17 | N/A | 6.5 MEDIUM |
| It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8. | |||||
| CVE-2025-1909 | 1 Buddyboss | 1 Buddyboss Platform | 2026-06-17 | N/A | 9.8 CRITICAL |
| The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email. | |||||
| CVE-2025-1882 | 1 I-drive | 4 I11, I11 Firmware, I12 and 1 more | 2026-06-17 | 4.3 MEDIUM | 5.0 MEDIUM |
| A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control for register interface. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life. | |||||
