Total
36333 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-21536 | 1 Microsoft | 1 Devices Pricing Program | 2026-06-17 | N/A | 9.8 CRITICAL |
| Microsoft Devices Pricing Program Remote Code Execution Vulnerability | |||||
| CVE-2026-21505 | 1 Color | 1 Iccdev | 2026-06-17 | N/A | 5.5 MEDIUM |
| iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV has undefined behavior due to an invalid enum value. This issue has been patched in version 2.3.1.2. | |||||
| CVE-2026-21033 | 1 Samsung | 1 Assistant | 2026-06-17 | N/A | 7.1 HIGH |
| Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | |||||
| CVE-2026-21032 | 1 Samsung | 1 Assistant | 2026-06-17 | N/A | 7.1 HIGH |
| Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | |||||
| CVE-2026-21030 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions. | |||||
| CVE-2026-21028 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information. | |||||
| CVE-2026-21023 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application. | |||||
| CVE-2026-21021 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.8 MEDIUM |
| Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity. | |||||
| CVE-2026-21014 | 1 Samsung | 1 Camera | 2026-06-17 | N/A | 2.8 LOW |
| Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability. | |||||
| CVE-2026-21012 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 3.3 LOW |
| External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege. | |||||
| CVE-2026-21010 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.6 MEDIUM |
| Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions. | |||||
| CVE-2026-21008 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.5 MEDIUM |
| Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information. | |||||
| CVE-2026-21006 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 2.4 LOW |
| Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents. | |||||
| CVE-2026-21004 | 1 Samsung | 1 Smart Switch | 2026-06-17 | N/A | 6.5 MEDIUM |
| Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service. | |||||
| CVE-2026-21003 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.8 MEDIUM |
| Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions. | |||||
| CVE-2026-20998 | 1 Samsung | 1 Smart Switch | 2026-06-17 | N/A | 9.8 CRITICAL |
| Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication. | |||||
| CVE-2026-20991 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.4 MEDIUM |
| Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents. | |||||
| CVE-2026-20985 | 1 Samsung | 1 Members | 2026-06-17 | N/A | 4.3 MEDIUM |
| Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability. | |||||
| CVE-2026-20981 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.6 MEDIUM |
| Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege. | |||||
| CVE-2026-20980 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.8 MEDIUM |
| Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands. | |||||
