Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-2101

A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary script code in user's browser session.

PUBLISHED
Vendor
Dassault Systèmes
Product
ENOVIAvpm Web Access
Provider severity
HIGH
Conflicts
0

CVE-2026-21009

Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21008

Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21007

Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21006

Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21005

Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Smart Switch
Provider severity
HIGH
Conflicts
0

CVE-2026-21004

Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.

PUBLISHED
Vendor
Samsung Mobile
Product
Smart Switch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21003

Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21002

Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.

PUBLISHED
Vendor
Samsung Mobile
Product
Galaxy Store
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21001

Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Galaxy Store
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21000

Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Galaxy Store
Provider severity
HIGH
Conflicts
0

CVE-2026-2100

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, p11-glue, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Update Infrastructure 5, Red Hat Hardened Images, p11-kit, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 7, Cost Management Metrics Operator 4, Red Hat Update Infrastructure 5, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Insights proxy 1.5
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20999

Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.

PUBLISHED
Vendor
Samsung Mobile
Product
Smart Switch
Provider severity
HIGH
Conflicts
0

CVE-2026-20998

Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.

PUBLISHED
Vendor
Samsung Mobile
Product
Smart Switch
Provider severity
HIGH
Conflicts
0

CVE-2026-20997

Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.

PUBLISHED
Vendor
Samsung Mobile
Product
Smart Switch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20996

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.

PUBLISHED
Vendor
Samsung Mobile
Product
Smart Switch
Provider severity
HIGH
Conflicts
0

CVE-2026-20995

Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.

PUBLISHED
Vendor
Samsung Mobile
Product
Smart Switch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20994

URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Account
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20993

Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Assistant
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20992

Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20991

Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20990

Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
0

CVE-2026-2099

AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.

PUBLISHED
Vendor
Flowring
Product
AgentFlow
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20989

Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20988

Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20987

Improper input validation in GalaxyDiagnostics prior to version 3.5.050 allows local privileged attackers to execute privileged commands.

PUBLISHED
Vendor
Samsung Mobile
Product
GalaxyDiagnostics
Provider severity
HIGH
Conflicts
0

CVE-2026-20986

Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members.

PUBLISHED
Vendor
Samsung Mobile
Product
Chinese Samsung Members
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20985

Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Members
Provider severity
HIGH
Conflicts
0

CVE-2026-20984

Improper handling of insufficient permission in Galaxy Wearable installed on non-Samsung Device prior to version 2.2.68 allows local attackers to access sensitive information.

PUBLISHED
Vendor
Samsung Mobile
Product
Galaxy Wearable
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20983

Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
0

CVE-2026-20982

Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20981

Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20980

Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
0

CVE-2026-2098

AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

PUBLISHED
Vendor
Flowring
Product
AgentFlow
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20979

Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
0

CVE-2026-20978

Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20977

Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20976

Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.

PUBLISHED
Vendor
Samsung Mobile
Product
Galaxy Store
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20975

Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Cloud
Provider severity
LOW
Conflicts
0

CVE-2026-20974

Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20973

Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20972

Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20971

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
HIGH
Conflicts
0

CVE-2026-20970

Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2097

Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

PUBLISHED
Vendor
Flowring
Product
Agentflow
Provider severity
HIGH
Conflicts
1

CVE-2026-20969

Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
LOW
Conflicts
0

CVE-2026-20968

Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Mobile Devices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20967

Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
System Center Operations Manager 2025, System Center Operations Manager 2022, System Center Operations Manager 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-20965

Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center in Azure Portal
Provider severity
HIGH
Conflicts
0

CVE-2026-20963

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition
Provider severity
CRITICAL
Conflicts
1