Vulnerabilities (CVE)

Filtered by vendor Samsung Subscribe
Total 1631 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-21010 1 Samsung 1 Android 2026-06-17 N/A 6.6 MEDIUM
Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.
CVE-2026-21009 1 Samsung 1 Android 2026-06-17 N/A 6.8 MEDIUM
Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.
CVE-2026-21008 1 Samsung 1 Android 2026-06-17 N/A 6.5 MEDIUM
Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.
CVE-2026-21007 1 Samsung 1 Android 2026-06-17 N/A 6.8 MEDIUM
Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.
CVE-2026-21006 1 Samsung 1 Android 2026-06-17 N/A 2.4 LOW
Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.
CVE-2026-21005 1 Samsung 1 Smart Switch 2026-06-17 N/A 6.5 MEDIUM
Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.
CVE-2026-21004 1 Samsung 1 Smart Switch 2026-06-17 N/A 6.5 MEDIUM
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
CVE-2026-21003 1 Samsung 1 Android 2026-06-17 N/A 6.8 MEDIUM
Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions.
CVE-2026-21002 1 Samsung 1 Galaxy Store 2026-06-17 N/A 5.5 MEDIUM
Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.
CVE-2026-21001 1 Samsung 1 Galaxy Store 2026-06-17 N/A 5.5 MEDIUM
Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
CVE-2026-21000 1 Samsung 1 Galaxy Store 2026-06-17 N/A 5.5 MEDIUM
Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
CVE-2026-20999 1 Samsung 1 Smart Switch 2026-06-17 N/A 7.5 HIGH
Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.
CVE-2026-20998 1 Samsung 1 Smart Switch 2026-06-17 N/A 9.8 CRITICAL
Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
CVE-2026-20997 1 Samsung 1 Smart Switch 2026-06-17 N/A 9.8 CRITICAL
Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.
CVE-2026-20996 1 Samsung 1 Smart Switch 2026-06-17 N/A 5.3 MEDIUM
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.
CVE-2026-20995 1 Samsung 1 Smart Switch 2026-06-17 N/A 5.3 MEDIUM
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
CVE-2026-20994 1 Samsung 1 Account 2026-06-17 N/A 6.1 MEDIUM
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
CVE-2026-20993 1 Samsung 1 Assistant 2026-06-17 N/A 5.5 MEDIUM
Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information.
CVE-2026-20992 1 Samsung 1 Android 2026-06-17 N/A 3.3 LOW
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
CVE-2026-20991 1 Samsung 1 Android 2026-06-17 N/A 4.4 MEDIUM
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.