Vulnerabilities (CVE)

Filtered by vendor Samsung Subscribe
Total 1672 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-25204 1 Samsung 1 Escargot 2026-06-17 N/A 6.2 MEDIUM
Deserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows denial of service condition via process abort. This issue affects escarogt prior to commit hash 97e8115ab1110bc502b4b5e4a0c689a71520d335
CVE-2026-25202 1 Samsung 1 Magicinfo 9 Server 2026-06-17 N/A 9.8 CRITICAL
The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1.
CVE-2026-25201 1 Samsung 1 Magicinfo 9 Server 2026-06-17 N/A 8.8 HIGH
An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1.
CVE-2026-25200 1 Samsung 1 Magicinfo 9 Server 2026-06-17 N/A 9.8 CRITICAL
A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1.
CVE-2026-21033 1 Samsung 1 Assistant 2026-06-17 N/A 7.1 HIGH
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
CVE-2026-21032 1 Samsung 1 Assistant 2026-06-17 N/A 7.1 HIGH
Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
CVE-2026-21031 1 Samsung 1 Android 2026-06-17 N/A 7.8 HIGH
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.
CVE-2026-21030 1 Samsung 1 Android 2026-06-17 N/A 7.8 HIGH
Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.
CVE-2026-21029 1 Samsung 1 Android 2026-06-17 N/A 7.8 HIGH
Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.
CVE-2026-21028 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
CVE-2026-21027 1 Samsung 1 Android 2026-06-17 N/A 3.3 LOW
Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.
CVE-2026-21026 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.
CVE-2026-21025 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
CVE-2026-21023 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
CVE-2026-21022 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
CVE-2026-21021 1 Samsung 1 Android 2026-06-17 N/A 6.8 MEDIUM
Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.
CVE-2026-21020 1 Samsung 1 Android 2026-06-17 N/A 7.8 HIGH
Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.
CVE-2026-21018 1 Samsung 1 Android 2026-06-17 N/A 6.7 MEDIUM
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.
CVE-2026-21017 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.
CVE-2026-21016 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.