Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2021-25420
Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi pass…
Galaxy Watch Plugin
2.2.05.21033151+
MEDIUM 5.5
CVE-2021-25421
Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi pas…
Galaxy Watch 3 Plugin
2.2.09.21033151+
MEDIUM 5.5
CVE-2021-25422
Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log permissions to leak Wi-Fi pass…
Watch Active Plugin
2.2.07.21033151+
MEDIUM 5.5
CVE-2021-25423
Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log permissions to leak Wi-Fi pas…
Watch Active2 Plugin
2.2.08.21033151+
HIGH 7.8
CVE-2021-25400
Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
Internet
14.0.1.20+
HIGH 7.8
CVE-2021-25401
Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.
Health
6.16+
HIGH 7.1
CVE-2021-25399
Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.
Smart Manager
11.0.05.0+
MEDIUM 6.5
CVE-2021-25406
Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device inf…
Gear S
2.2.05.20122441+
MEDIUM 6.4
CVE-2021-25395 KEV
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is co…
Android
Mitigation only
MEDIUM 5.5
CVE-2021-25405
An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrusted applications to access loc…
Notes
4.2.04.27+
MEDIUM 6.4
CVE-2021-25394 KEV
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privileg…
Android
Mitigation only
MEDIUM 6.5
CVE-2020-26144
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long…
Galaxy I9305 Firmware
10.0.1-31 / 11.0.0-36+
MEDIUM 6.5
CVE-2020-26145
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcas…
Galaxy I9305 Firmware
1.2+
MEDIUM 5.3
CVE-2020-26146EPSS 6%
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive p…
Galaxy I9305 Firmware
10.0.1-31 / 11.0.0-36+
HIGH 7.8
CVE-2021-25373
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10…
Customization Service
2.2.02.1 / 2.4.03.0+
HIGH 7.8
CVE-2021-25377
Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to …
Experience Service
after 10.8.0.4
HIGH 7.8
CVE-2021-25381
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows loca…
Account
Mitigation only
HIGH 7.5
CVE-2021-25374
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and…
Members
after 2.4.83.9
HIGH 7.3
CVE-2021-25380
Improper handling of exceptional conditions in Bixby prior to version 3.0.53.02 allows attacker to execute the actions registered by the user.
Bixby
3.0.53.02+
MEDIUM 6.5
CVE-2021-25375
Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when …
Email
6.1.14.0+
MEDIUM 5.3
CVE-2021-25376
An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotia…
Email
6.1.41.0+
MEDIUM 5.3
CVE-2021-25378
Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.
Smartthings
1.7.63.6+
MEDIUM 6.7
CVE-2021-25371 KEV
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
Android
Mitigation only
MEDIUM 6.7
CVE-2021-25372 KEV
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
Android
Mitigation only
MEDIUM 5.5
CVE-2021-25369 KEV
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
Android
Mitigation only
HIGH 7.5
CVE-2021-25368
Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.
Cloud
4.7.0.3+
MEDIUM 5.4
CVE-2021-25367
Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission.
Notes
4.2.00.22+
HIGH 7.8
CVE-2021-25349
Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijackin…
Slow Motion Editor
3.5.18.5+
HIGH 7.8
CVE-2021-25352
Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and mod…
Bixby Voice
3.0.52.14+
HIGH 7.8
CVE-2021-25355
Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking th…
Notes
4.2.00.22+