Vulnerability index

Browse CVEs

43 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Mcp Toolbox For Databases HIGH 7.5
CVE-2026-14541

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When…

No fix yet
Fix from $1,950 2026-07-31
Mcp Toolbox For Databases CRITICAL 9.1
CVE-2026-11717

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When veri…

Patch available
Fix from $2,300 2026-06-18
Mcp Toolbox For Databases CRITICAL 9.1
CVE-2026-11718

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the …

Patch available
Fix from $2,300 2026-06-18
Android HIGH 8.8
CVE-2025-26438

In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a pr…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.3
CVE-2024-40653

In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error…

Mitigation only
Fix from $1,950 2025-09-02
Chrome Os MEDIUM 6.1
CVE-2025-6044

An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a p…

Mitigation only
Fix from $1,600 2025-07-07
Android HIGH 7.3
CVE-2024-29757

there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execu…

Mitigation only
Fix from $1,950 2024-04-05
Android MEDIUM 5.0
CVE-2023-21307

In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypas…

Fix: 14.0+
Fix from $1,600 2023-10-30
Nest Hub Max Firmware HIGH 8.8
CVE-2023-2626

There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes …

Fix: 1.56.368671 / 1.63.355999+
Fix from $1,950 2023-07-25
Espv2 CRITICAL 9.8
CVE-2023-30845

ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 through 2.42.0 contains an authe…

Fix: 2.43.0+
Fix from $2,300 2023-04-26
Android HIGH 7.5
CVE-2023-21027

In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lea…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.5
CVE-2023-21419

An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain co…

Mitigation only
Fix from $1,950 2023-02-09
Android MEDIUM 6.8
CVE-2023-20924

In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of privilege w…

Mitigation only
Fix from $1,600 2023-01-26
Android HIGH 7.1
CVE-2022-33732

Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unpro…

Mitigation only
Fix from $1,950 2022-08-05
Android HIGH 7.8
CVE-2022-30755

Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the…

Mitigation only
Fix from $1,950 2022-07-12
Android MEDIUM 6.8
CVE-2022-25832

Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authent…

Mitigation only
Fix from $1,600 2022-04-11
Android MEDIUM 6.8
CVE-2022-26091

Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a fu…

Mitigation only
Fix from $1,600 2022-04-11
Android HIGH 7.8
CVE-2022-23729

When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.

Fix: 11.0+
Fix from $1,950 2022-03-04
Android MEDIUM 6.0
CVE-2021-25490

A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.

Mitigation only
Fix from $1,600 2021-10-06
Android HIGH 7.8
CVE-2021-0595

In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. Thi…

Patch available
Fix from $1,950 2021-10-06
Chrome Os Readiness Tool HIGH 7.8
CVE-2021-30605

Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing …

Fix: 1.0.2.0+
Fix from $1,950 2021-09-08
Android MEDIUM 6.1
CVE-2021-25389

Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.

Mitigation only
Fix from $1,600 2021-06-11
Android MEDIUM 5.3
CVE-2021-25347

Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is execu…

No fix yet
Fix from $1,600 2021-03-04
Android HIGH 7.5
CVE-2020-0460

In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This cou…

Patch available
Fix from $1,950 2020-12-14
Android CRITICAL 9.8
CVE-2018-21038

An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsu…

Mitigation only
Fix from $2,300 2020-04-08
Android HIGH 7.5
CVE-2017-18654

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0, 7.1) software. An unauthenticated attacker can register a new security certi…

Mitigation only
Fix from $1,950 2020-04-07
Android HIGH 7.5
CVE-2016-11042

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The Samsung ID is SVE-2016-5381 (J…

No fix yet
Fix from $1,950 2020-04-07
Android HIGH 7.5
CVE-2019-20618

An issue was discovered on Samsung mobile devices with P(9.0) software. The Pin Window feature allows unauthenticated unpinning of an app. The Samsun…

Mitigation only
Fix from $1,950 2020-03-24
Android HIGH 7.5
CVE-2019-20620

An issue was discovered on Samsung mobile devices with P(9.0) software. The Settings application allows unauthenticated changes. The Samsung IDs are …

Mitigation only
Fix from $1,950 2020-03-24
Android HIGH 7.5
CVE-2019-20565

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Attackers can change the USB configuration without authentication.…

Mitigation only
Fix from $1,950 2020-03-24