Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 36333 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-21536 1 Microsoft 1 Devices Pricing Program 2026-06-17 N/A 9.8 CRITICAL
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
CVE-2026-21505 1 Color 1 Iccdev 2026-06-17 N/A 5.5 MEDIUM
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV has undefined behavior due to an invalid enum value. This issue has been patched in version 2.3.1.2.
CVE-2026-21033 1 Samsung 1 Assistant 2026-06-17 N/A 7.1 HIGH
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
CVE-2026-21032 1 Samsung 1 Assistant 2026-06-17 N/A 7.1 HIGH
Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
CVE-2026-21030 1 Samsung 1 Android 2026-06-17 N/A 7.8 HIGH
Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.
CVE-2026-21028 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
CVE-2026-21023 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
CVE-2026-21021 1 Samsung 1 Android 2026-06-17 N/A 6.8 MEDIUM
Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.
CVE-2026-21014 1 Samsung 1 Camera 2026-06-17 N/A 2.8 LOW
Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability.
CVE-2026-21012 1 Samsung 1 Android 2026-06-17 N/A 3.3 LOW
External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.
CVE-2026-21010 1 Samsung 1 Android 2026-06-17 N/A 6.6 MEDIUM
Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.
CVE-2026-21008 1 Samsung 1 Android 2026-06-17 N/A 6.5 MEDIUM
Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.
CVE-2026-21006 1 Samsung 1 Android 2026-06-17 N/A 2.4 LOW
Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.
CVE-2026-21004 1 Samsung 1 Smart Switch 2026-06-17 N/A 6.5 MEDIUM
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
CVE-2026-21003 1 Samsung 1 Android 2026-06-17 N/A 6.8 MEDIUM
Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions.
CVE-2026-20998 1 Samsung 1 Smart Switch 2026-06-17 N/A 9.8 CRITICAL
Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
CVE-2026-20991 1 Samsung 1 Android 2026-06-17 N/A 4.4 MEDIUM
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
CVE-2026-20985 1 Samsung 1 Members 2026-06-17 N/A 4.3 MEDIUM
Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.
CVE-2026-20981 1 Samsung 1 Android 2026-06-17 N/A 6.6 MEDIUM
Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.
CVE-2026-20980 1 Samsung 1 Android 2026-06-17 N/A 6.8 MEDIUM
Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.