Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-14541
An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When…
Mcp Toolbox For Databases
No fix yet
CRITICAL 9.1
CVE-2026-11717
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox.
When veri…
Mcp Toolbox For Databases
Patch available
CRITICAL 9.1
CVE-2026-11718
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox.
When the …
Mcp Toolbox For Databases
Patch available
HIGH 8.8
CVE-2025-26438
In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a pr…
Android
Patch available
HIGH 7.3
CVE-2024-40653
In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error…
Android
Mitigation only
MEDIUM 6.1
CVE-2025-6044
An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a p…
Chrome Os
Mitigation only
HIGH 7.3
CVE-2024-29757
there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execu…
Android
Mitigation only
MEDIUM 5.0
CVE-2023-21307
In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypas…
Android
14.0+
HIGH 8.8
CVE-2023-2626
There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes …
Nest Hub Max Firmware
1.56.368671 / 1.63.355999+
CRITICAL 9.8
CVE-2023-30845
ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 through 2.42.0 contains an authe…
Espv2
2.43.0+
HIGH 7.5
CVE-2023-21027
In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lea…
Android
Mitigation only
HIGH 7.5
CVE-2023-21419
An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain co…
Android
Mitigation only
MEDIUM 6.8
CVE-2023-20924
In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of privilege w…
Android
Mitigation only
HIGH 7.1
CVE-2022-33732
Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unpro…
Android
Mitigation only
HIGH 7.8
CVE-2022-30755
Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the…
Android
Mitigation only
MEDIUM 6.8
CVE-2022-25832
Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authent…
Android
Mitigation only
MEDIUM 6.8
CVE-2022-26091
Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a fu…
Android
Mitigation only
HIGH 7.8
CVE-2022-23729
When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.
Android
11.0+
MEDIUM 6.0
CVE-2021-25490
A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.
Android
Mitigation only
HIGH 7.8
CVE-2021-0595
In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. Thi…
Android
Patch available
HIGH 7.8
CVE-2021-30605
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing …
Chrome Os Readiness Tool
1.0.2.0+
MEDIUM 6.1
CVE-2021-25389
Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.
Android
Mitigation only
MEDIUM 5.3
CVE-2021-25347
Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is execu…
Android
No fix yet
HIGH 7.5
CVE-2020-0460
In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This cou…
Android
Patch available
CRITICAL 9.8
CVE-2018-21038
An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsu…
Android
Mitigation only
HIGH 7.5
CVE-2017-18654
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0, 7.1) software. An unauthenticated attacker can register a new security certi…
Android
Mitigation only
HIGH 7.5
CVE-2016-11042
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The Samsung ID is SVE-2016-5381 (J…
Android
No fix yet
HIGH 7.5
CVE-2019-20618
An issue was discovered on Samsung mobile devices with P(9.0) software. The Pin Window feature allows unauthenticated unpinning of an app. The Samsun…
Android
Mitigation only
HIGH 7.5
CVE-2019-20620
An issue was discovered on Samsung mobile devices with P(9.0) software. The Settings application allows unauthenticated changes. The Samsung IDs are …
Android
Mitigation only
HIGH 7.5
CVE-2019-20565
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Attackers can change the USB configuration without authentication.…
Android
Mitigation only