← Back

Samsung

samsung

1,527 CVEs • 2,868 products

Products (2,868)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Assistant
assistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,527)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Magician
Jun 17, 2026
Sep 2, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process.
1Samsung
1Galaxy Wearable
Jun 17, 2026
Aug 6, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.
1Samsung
1Blockchain Keystore
Jun 17, 2026
Aug 6, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
1Samsung
1Blockchain Keystore
Jun 17, 2026
Aug 6, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
1Samsung
1Health
Jun 17, 2026
Aug 6, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.
1Samsung
1Blockchain Keystore
Jun 17, 2026
Aug 6, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.
1Samsung
1Blockchain Keystore
Jun 17, 2026
Aug 6, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
1Samsung
1Android
Jun 17, 2026
Aug 6, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
1Samsung
1Android
Jun 17, 2026
Aug 6, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.
1Samsung
1Android
Jun 17, 2026
Aug 6, 2025
N/A· v4
6.0 MEDIUM· v3
N/A· v2
Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.
1Samsung
1Android
Jun 17, 2026
Aug 6, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.
1Samsung
7Exynos 1280 Firmware
Exynos 1330 FirmwareExynos 1380 Firmware+4 more
Jun 17, 2026
Aug 4, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leads to an out-of-bound write.
1Samsung
1Data Management Server Firmware
Jun 17, 2026
Jul 29, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP ad...Show more
An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.Show less
1Samsung
1Data Management Server Firmware
Jun 17, 2026
Jul 29, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addr...Show more
An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.Show less
1Samsung
1Data Management Server Firmware
Jun 17, 2026
Jul 29, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem
1Samsung
1Data Management Server Firmware
Jun 17, 2026
Jul 29, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files
1Samsung
1Data Management Server Firmware
Jun 17, 2026
Jul 29, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system
1Samsung
1Data Management Server Firmware
Jun 17, 2026
Jul 29, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerabi...Show more
An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability.Show less
1Samsung
1Magicinfo 9 Server
Jun 17, 2026
Jul 23, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.
1Samsung
1Magicinfo 9 Server
Jun 17, 2026
Jul 23, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.