Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Account HIGH 7.5
CVE-2023-21481

Improper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitive informa…

Fix: 14.1.0.0+
Fix from $1,950 2025-09-03
Android MEDIUM 5.5
CVE-2023-21477

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access prote…

Mitigation only
Fix from $1,600 2025-09-03
Android MEDIUM 5.5
CVE-2023-21478

Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

Mitigation only
Fix from $1,600 2025-09-03
Android MEDIUM 5.3
CVE-2023-21479

Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to regis…

Mitigation only
Fix from $1,600 2025-09-03
Android HIGH 7.8
CVE-2023-21475

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

Mitigation only
Fix from $1,950 2025-09-03
Android HIGH 7.8
CVE-2023-21476

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

Mitigation only
Fix from $1,950 2025-09-03
Android HIGH 7.1
CVE-2023-21474

Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.

Mitigation only
Fix from $1,950 2025-09-03
Android MEDIUM 6.8
CVE-2023-21472

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in …

Mitigation only
Fix from $1,600 2025-09-03
Android MEDIUM 6.8
CVE-2023-21473

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in …

Mitigation only
Fix from $1,600 2025-09-03
Exynos CRITICAL 9.8
CVE-2023-21467

Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.

Mitigation only
Fix from $2,300 2025-09-03
Android HIGH 7.8
CVE-2023-21468

Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.

Mitigation only
Fix from $1,950 2025-09-03
Exynos 980 Firmware MEDIUM 6.5
CVE-2025-32100

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 24…

Mitigation only
Fix from $1,600 2025-09-02
Magician MEDIUM 5.3
CVE-2025-32098

An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insec…

Fix: after 8.3.0
Fix from $1,600 2025-09-02
Galaxy Wearable MEDIUM 5.5
CVE-2025-21022

Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.

Fix: 2.2.63.25042861+
Fix from $1,600 2025-08-06
Android HIGH 7.1
CVE-2025-21015

Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.

Mitigation only
Fix from $1,950 2025-08-06
Blockchain Keystore MEDIUM 6.7
CVE-2025-21017

Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds…

Fix: 1.3.17.2+
Fix from $1,600 2025-08-06
Blockchain Keystore MEDIUM 6.7
CVE-2025-21020

Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-boun…

Fix: 1.3.17.2+
Fix from $1,600 2025-08-06
Blockchain Keystore MEDIUM 6.7
CVE-2025-21021

Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memor…

Fix: 1.3.17.2+
Fix from $1,600 2025-08-06
Health MEDIUM 5.5
CVE-2025-21019

Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is req…

Fix: 6.30.1.003+
Fix from $1,600 2025-08-06
Android MEDIUM 6.0
CVE-2025-21010

Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.

Mitigation only
Fix from $1,600 2025-08-06
Android MEDIUM 5.5
CVE-2025-21014

Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive informat…

Mitigation only
Fix from $1,600 2025-08-06
Exynos 2100 Firmware MEDIUM 6.5
CVE-2024-45183

An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leads to an ou…

Mitigation only
Fix from $1,600 2025-08-04
Data Management Server Firmware CRITICAL 9.1
CVE-2025-53082

An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the files…

Fix: 2.3.13.1 / 2.6.14.1+
Fix from $2,300 2025-07-29
Data Management Server Firmware CRITICAL 9.1
CVE-2025-53081

An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesys…

Fix: 2.3.13.1 / 2.6.14.1+
Fix from $2,300 2025-07-29
Data Management Server Firmware MEDIUM 6.5
CVE-2025-53080

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers …

Fix: 2.3.13.1 / 2.6.14.1+
Fix from $1,600 2025-07-29
Data Management Server Firmware CRITICAL 9.8
CVE-2025-53078

Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system

Fix: 2.3.13.1 / 2.6.14.1+
Fix from $2,300 2025-07-29
Data Management Server Firmware MEDIUM 6.5
CVE-2025-53077

An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker cou…

Fix: 2.3.13.1 / 2.6.14.1+
Fix from $1,600 2025-07-29
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54455

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Ser…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54448

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54449

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23