Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 15 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:Samsung Health Relative Path Traversal Information Disclosure

Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

CWE-23Aug 10, 2026
CVSS6.9v4.0EPSS0.137%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Health Incorrect Authorization Information Disclosure

Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

CWE-863Aug 10, 2026
CVSS6.9v4.0EPSS0.105%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Health Incorrect Authorization

Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

CWE-863Aug 10, 2026
CVSS6.9v4.0EPSS0.105%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Health Improper Authorization

Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device information.

CWE-285Jul 10, 2026
CVSS4.8v4.0EPSS0.099%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.

CWE-285Oct 10, 2025
CVSS6.2v3.1EPSS0.11%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.

CWE-285Aug 6, 2025
CVSS5.5v3.1EPSS0.135%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this vulnerability.

CWE-20Jul 2, 2024
CVSS4.4v3.1EPSS0.154%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data.

CWE-284Nov 7, 2023
CVSS4.7v3.1EPSS0.16%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.

CWE-284Oct 4, 2023
CVSS4.0v3.1EPSS0.167%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.

CWE-284Oct 4, 2023
CVSS4.0v3.1EPSS0.167%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper input validation vulnerability in Samsung Health prior to version 6.24.2.011 allows attackers to write arbitrary file with Samsung Health privilege.

CWE-20Sep 6, 2023
CVSS5.5v3.1EPSS0.36%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.

CWE-287CWE-613Jan 7, 2022
CVSS2.8v3.1EPSS0.204%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.

CWE-287CWE-863Nov 5, 2021
CVSS4.0v3.1EPSS0.19%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.

CWE-20CWE-863Jun 11, 2021
CVSS-v3.1EPSS0.261%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exported component.

CWE-703CWE-754Jun 11, 2021
CVSS-v3.1EPSS0.793%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX