Vulnerabilities (CVE)

Filtered by vendor Samsung Subscribe
Total 1672 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-20995 1 Samsung 1 Smart Switch 2026-06-17 N/A 5.3 MEDIUM
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
CVE-2026-20994 1 Samsung 1 Account 2026-06-17 N/A 6.1 MEDIUM
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
CVE-2026-20993 1 Samsung 1 Assistant 2026-06-17 N/A 5.5 MEDIUM
Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information.
CVE-2026-20992 1 Samsung 1 Android 2026-06-17 N/A 3.3 LOW
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
CVE-2026-20991 1 Samsung 1 Android 2026-06-17 N/A 4.4 MEDIUM
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
CVE-2026-20990 1 Samsung 1 Android 2026-06-17 N/A 8.1 HIGH
Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege.
CVE-2026-20989 1 Samsung 1 Android 2026-06-17 N/A 2.4 LOW
Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.
CVE-2026-20988 1 Samsung 1 Android 2026-06-17 N/A 5.0 MEDIUM
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability.
CVE-2026-20986 1 Samsung 1 Members 2026-06-17 N/A 5.5 MEDIUM
Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members.
CVE-2026-20985 1 Samsung 1 Members 2026-06-17 N/A 4.3 MEDIUM
Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.
CVE-2026-20983 1 Samsung 1 Android 2026-06-17 N/A 7.8 HIGH
Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege.
CVE-2026-20982 1 Samsung 1 Android 2026-06-17 N/A 6.0 MEDIUM
Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.
CVE-2026-20981 1 Samsung 1 Android 2026-06-17 N/A 6.6 MEDIUM
Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.
CVE-2026-20980 1 Samsung 1 Android 2026-06-17 N/A 6.8 MEDIUM
Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.
CVE-2026-20979 1 Samsung 1 Android 2026-06-17 N/A 7.8 HIGH
Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege.
CVE-2026-20978 1 Samsung 1 Android 2026-06-17 N/A 6.1 MEDIUM
Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.
CVE-2026-20977 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.
CVE-2026-20976 1 Samsung 1 Galaxy Store 2026-06-17 N/A 7.8 HIGH
Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.
CVE-2026-20975 1 Samsung 1 Cloud 2026-06-17 N/A 5.5 MEDIUM
Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.
CVE-2026-20974 1 Samsung 1 Android 2026-06-17 N/A 4.6 MEDIUM
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.