Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54450

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code In…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54451

Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue af…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54452

Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: l…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54453

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code In…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54454

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Ser…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54442

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54443

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload …

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54444

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54445EPSS 10%

Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54446

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload …

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54447

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server HIGH 8.8
CVE-2025-54441EPSS 8%

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $1,950 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54440

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server HIGH 8.8
CVE-2025-54439EPSS 7%

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $1,950 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54438

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload …

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Android HIGH 7.8
CVE-2025-21006

Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds mem…

Fix: 15.0+
Fix from $1,950 2025-07-08
Android MEDIUM 5.5
CVE-2025-21005

Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.

Fix: 15.0+
Fix from $1,600 2025-07-08
Android MEDIUM 5.5
CVE-2025-21007

Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

Fix: 15.0+
Fix from $1,600 2025-07-08
Android MEDIUM 5.5
CVE-2025-21008

Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

Fix: 15.0+
Fix from $1,600 2025-07-08
Android MEDIUM 5.5
CVE-2025-21009

Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

Fix: 15.0+
Fix from $1,600 2025-07-08
Wear Os MEDIUM 5.5
CVE-2025-20997

Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Gala…

Mitigation only
Fix from $1,600 2025-07-08
Android MEDIUM 5.5
CVE-2025-21001

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.

Mitigation only
Fix from $1,600 2025-07-08
Android MEDIUM 5.5
CVE-2025-21002

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.

Mitigation only
Fix from $1,600 2025-07-08
Android MEDIUM 5.5
CVE-2025-21003

Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.

Mitigation only
Fix from $1,600 2025-07-08
Wear Os MEDIUM 5.5
CVE-2025-21004

Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power o…

Mitigation only
Fix from $1,600 2025-07-08
Android MEDIUM 6.7
CVE-2025-20982

Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bo…

Mitigation only
Fix from $1,600 2025-07-08
Android MEDIUM 6.7
CVE-2025-20983

Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-b…

Mitigation only
Fix from $1,600 2025-07-08
Exynos 980 Firmware CRITICAL 9.1
CVE-2025-47202

In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W…

Mitigation only
Fix from $2,300 2025-07-07
Exynos 2400 Firmware HIGH 7.5
CVE-2025-26780

An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a Denial of Servi…

Mitigation only
Fix from $1,950 2025-07-07
Rlottie CRITICAL 9.8
CVE-2025-53076

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.

Patch available
Fix from $2,300 2025-06-30