← Back

Samsung

samsung

1,527 CVEs • 2,868 products

Products (2,868)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Assistant
assistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,527)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Smart Switch
Jun 17, 2026
Mar 16, 2026
5.3 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
1Samsung
1Account
Jun 17, 2026
Mar 16, 2026
6.9 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
1Samsung
1Assistant
Jun 17, 2026
Mar 16, 2026
4.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information.
1Samsung
1Android
Jun 17, 2026
Mar 16, 2026
4.8 MEDIUM· v4
3.3 LOW· v3
N/A· v2
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
1Samsung
1Android
Jun 17, 2026
Mar 16, 2026
6.7 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
1Samsung
1Android
Jun 17, 2026
Mar 16, 2026
8.4 HIGH· v4
8.1 HIGH· v3
N/A· v2
Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege.
1Samsung
1Android
Jun 17, 2026
Mar 16, 2026
5.1 MEDIUM· v4
2.4 LOW· v3
N/A· v2
Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.
1Samsung
1Android
Jun 17, 2026
Mar 16, 2026
6.8 MEDIUM· v4
5.0 MEDIUM· v3
N/A· v2
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering th...Show more
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability.Show less
1Samsung
7Exynos 1280 Firmware
Exynos 1380 FirmwareExynos 1480 Firmware+4 more
Jun 17, 2026
Mar 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service.
1Samsung
7Exynos 1280 Firmware
Exynos 1380 FirmwareExynos 1480 Firmware+4 more
Jun 17, 2026
Mar 3, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4L_VERTEXIOC_BOOTUP input leads to a denial of service.
1Samsung
1Exynos 2200 Firmware
Jun 17, 2026
Mar 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization within DL NAS Transport messages.
1Samsung
5Exynos 1380 Firmware
Exynos 1480 FirmwareExynos 1580 Firmware+2 more
Jun 17, 2026
Mar 3, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.ast.thread_ref in set_cpu_affinity() causes a denial of service.
1Samsung
5Exynos 1280 Firmware
Exynos 1380 FirmwareExynos 1480 Firmware+2 more
Jun 17, 2026
Mar 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference of ft_handle in load_fw_utc_vector() causes a denial of service.
1Samsung
1Members
Jun 17, 2026
Feb 4, 2026
5.1 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members.
1Samsung
1Members
Jun 17, 2026
Feb 4, 2026
7.0 HIGH· v4
4.3 MEDIUM· v3
N/A· v2
Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for trig...Show more
Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.Show less
1Samsung
1Android
Jun 17, 2026
Feb 4, 2026
8.4 HIGH· v4
7.8 HIGH· v3
N/A· v2
Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege.
1Samsung
1Android
Jun 17, 2026
Feb 4, 2026
6.8 MEDIUM· v4
6.0 MEDIUM· v3
N/A· v2
Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.
1Samsung
1Android
Jun 17, 2026
Feb 4, 2026
5.4 MEDIUM· v4
6.6 MEDIUM· v3
N/A· v2
Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.
1Samsung
1Android
Jun 17, 2026
Feb 4, 2026
7.0 HIGH· v4
6.8 MEDIUM· v3
N/A· v2
Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.
1Samsung
1Android
Jun 17, 2026
Feb 4, 2026
8.4 HIGH· v4
7.8 HIGH· v3
N/A· v2
Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege.