Vulnerability index

Browse CVEs

43 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2026-14541 An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When… Mcp Toolbox For Databases No fix yet Fix from $1,9502026-07-31 CRITICAL 9.1 CVE-2026-11717 An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When veri… Mcp Toolbox For Databases Patch available Fix from $2,3002026-06-18 CRITICAL 9.1 CVE-2026-11718 An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the … Mcp Toolbox For Databases Patch available Fix from $2,3002026-06-18 HIGH 8.8 CVE-2025-26438 In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a pr… Android Patch available Fix from $1,9502025-09-04 HIGH 7.3 CVE-2024-40653 In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error… Android Mitigation only Fix from $1,9502025-09-02 MEDIUM 6.1 CVE-2025-6044 An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a p… Chrome Os Mitigation only Fix from $1,6002025-07-07 HIGH 7.3 CVE-2024-29757 there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execu… Android Mitigation only Fix from $1,9502024-04-05 MEDIUM 5.0 CVE-2023-21307 In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypas… Android 14.0+ Fix from $1,6002023-10-30 HIGH 8.8 CVE-2023-2626 There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes … Nest Hub Max Firmware 1.56.368671 / 1.63.355999+ Fix from $1,9502023-07-25 CRITICAL 9.8 CVE-2023-30845 ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 through 2.42.0 contains an authe… Espv2 2.43.0+ Fix from $2,3002023-04-26 HIGH 7.5 CVE-2023-21027 In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lea… Android Mitigation only Fix from $1,9502023-03-24 HIGH 7.5 CVE-2023-21419 An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain co… Android Mitigation only Fix from $1,9502023-02-09 MEDIUM 6.8 CVE-2023-20924 In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of privilege w… Android Mitigation only Fix from $1,6002023-01-26 HIGH 7.1 CVE-2022-33732 Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unpro… Android Mitigation only Fix from $1,9502022-08-05 HIGH 7.8 CVE-2022-30755 Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the… Android Mitigation only Fix from $1,9502022-07-12 MEDIUM 6.8 CVE-2022-25832 Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authent… Android Mitigation only Fix from $1,6002022-04-11 MEDIUM 6.8 CVE-2022-26091 Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a fu… Android Mitigation only Fix from $1,6002022-04-11 HIGH 7.8 CVE-2022-23729 When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010. Android 11.0+ Fix from $1,9502022-03-04 MEDIUM 6.0 CVE-2021-25490 A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process. Android Mitigation only Fix from $1,6002021-10-06 HIGH 7.8 CVE-2021-0595 In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. Thi… Android Patch available Fix from $1,9502021-10-06 HIGH 7.8 CVE-2021-30605 Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing … Chrome Os Readiness Tool 1.0.2.0+ Fix from $1,9502021-09-08 MEDIUM 6.1 CVE-2021-25389 Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication. Android Mitigation only Fix from $1,6002021-06-11 MEDIUM 5.3 CVE-2021-25347 Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is execu… Android No fix yet Fix from $1,6002021-03-04 HIGH 7.5 CVE-2020-0460 In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This cou… Android Patch available Fix from $1,9502020-12-14 CRITICAL 9.8 CVE-2018-21038 An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsu… Android Mitigation only Fix from $2,3002020-04-08 HIGH 7.5 CVE-2017-18654 An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0, 7.1) software. An unauthenticated attacker can register a new security certi… Android Mitigation only Fix from $1,9502020-04-07 HIGH 7.5 CVE-2016-11042 An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The Samsung ID is SVE-2016-5381 (J… Android No fix yet Fix from $1,9502020-04-07 HIGH 7.5 CVE-2019-20618 An issue was discovered on Samsung mobile devices with P(9.0) software. The Pin Window feature allows unauthenticated unpinning of an app. The Samsun… Android Mitigation only Fix from $1,9502020-03-24 HIGH 7.5 CVE-2019-20620 An issue was discovered on Samsung mobile devices with P(9.0) software. The Settings application allows unauthenticated changes. The Samsung IDs are … Android Mitigation only Fix from $1,9502020-03-24 HIGH 7.5 CVE-2019-20565 An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Attackers can change the USB configuration without authentication.… Android Mitigation only Fix from $1,9502020-03-24