CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-21043HIGH | Samsung Mobile Devices Out-of-Bounds Write VulnerabilityOut-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. CWE-787Sep 12, 2025 | CVSS8.8v3.1 | EPSS1.91% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21042HIGH | Samsung Mobile Devices Out-of-Bounds Write VulnerabilityOut-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. CWE-787Sep 12, 2025 | CVSS8.8v3.1 | EPSS33.2% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21492MEDIUM | Samsung Mobile Devices Insertion of Sensitive Information Into Log File VulnerabilityKernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. CWE-532May 4, 2023 | CVSS4.4v3.1 | EPSS2.55% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-22265MEDIUM | Samsung Mobile Devices Use-After-Free VulnerabilityAn improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution. | CVSS5.0v3.1 | EPSS0.392% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Samsung Mobile Devices Improper Input Validation VulnerabilityAssuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic. | CVSS3.3v3.1 | EPSS0.531% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2021-25487HIGH | Samsung Mobile Devices Out-of-Bounds Read VulnerabilityLack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer. CWE-125Oct 6, 2021 | CVSS7.3v3.1 | EPSS0.635% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25394MEDIUM | Samsung Mobile Devices Race Condition VulnerabilityA use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised. | CVSS6.4v3.1 | EPSS0.401% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25395MEDIUM | Samsung Mobile Devices Race Condition VulnerabilityA race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised. CWE-362Jun 11, 2021 | CVSS6.4v3.1 | EPSS0.366% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25372MEDIUM | Samsung Mobile Devices Improper Boundary Check VulnerabilityAn improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. | CVSS6.1v3.1 | EPSS0.804% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25371MEDIUM | Samsung Mobile Devices Unspecified VulnerabilityA vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. CWE-912Mar 26, 2021 | CVSS6.1v3.1 | EPSS0.802% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25370MEDIUM | Samsung Mobile Devices Memory Corruption VulnerabilityAn incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic. | CVSS6.1v3.1 | EPSS0.89% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25369MEDIUM | Samsung Mobile Devices Improper Access Control VulnerabilityAn improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. | CVSS6.2v3.1 | EPSS1.12% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25337MEDIUM | Samsung Mobile Devices Improper Access Control VulnerabilityImproper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files. | CVSS4.4v3.1 | EPSS2.83% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |