Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-21056

Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Health
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21055

Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Bixby
Provider severity
HIGH
Conflicts
0

CVE-2026-21054

Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.

PUBLISHED
Vendor
Samsung Mobile
Product
InputSharing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21053

Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within the application sandbox.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Email
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21052

Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21051

Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21050

Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2105

A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/deleteDept of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\DeptController.java of the component Department Management. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. This product takes the approach of rolling releases

PUBLISHED
Vendor
yeqifu
Product
warehouse
Provider severity
MEDIUM
Conflicts
2

CVE-2026-21049

Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
0

CVE-2026-21048

Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
0

CVE-2026-21047

Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
1

CVE-2026-21046

Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
0

CVE-2026-21045

Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
0

CVE-2026-21044

Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21043

Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system server privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21042

Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
0

CVE-2026-21041

Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21040

Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2104

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to other users via CSV export due to insufficient authorization checks.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21039

Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21038

Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Android USB Driver for Windows
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21037

Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Members
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21036

Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Internet
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21035

Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Plus TV
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21034

Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Auto
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21033

Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Assistant
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21032

Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Assistant
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21031

Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21030

Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2103

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and database can decrypt all stored credentials.

PUBLISHED
Vendor
Infor
Product
SyteLine ERP
Provider severity
HIGH
Conflicts
0

CVE-2026-21029

Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21028

Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21027

Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21026

Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21025

Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21024

Improper privilege management in Samsung System Support Service prior to version 8.0.8.0 allows local attackers to trigger privileged functions.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung System Support Service
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21023

Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21022

Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21021

Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21020

Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21019

Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to execute arbitrary code with system privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
0

CVE-2026-21018

Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21017

Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21016

Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21015

Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21014

Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Camera
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21013

Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Galaxy Wearable
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21012

External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21011

Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21010

Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0