CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-21073MEDIUM | Generated title:Samsung Galaxy Themes Improper Input Validation VulnerabilityImproper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. CWE-20Aug 10, 2026 | CVSS5.2v4.0 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21072MEDIUM | Generated title:Samsung libsavsvc.so VC1 Codec Out-of-Bounds WriteImproper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21071MEDIUM | Generated title:Samsung Mobile Devices libsavsvc.so MPEG4 Codec Out-of-Bounds WriteImproper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21070MEDIUM | Generated title:Samsung Mobile Devices Improper Input Validation in Samsung MessageImproper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.145% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21069MEDIUM | Generated title:Samsung libsavsvc.so VC1 Codec Out-of-Bounds WriteIncorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-681Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21068HIGH | Generated title:Samsung Mobile Devices libril_sem.so Stack-based Buffer OverflowStack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. CWE-121Aug 10, 2026 | CVSS8.4v4.0 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21067MEDIUM | Generated title:Samsung Mobile Devices libsmsd.so Out-of-Bounds WriteImproper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21066MEDIUM | Generated title:Samsung libcodec2_sec_flacdec.so Improper Input Validation Leading to Out-of-Bounds WriteImproper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS5.1v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21065MEDIUM | Generated title:Samsung Mobile libcodec2secqcelpdec Out-of-Bounds WriteOut-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. CWE-20Aug 10, 2026 | CVSS4.4v4.0 | EPSS0.106% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21064HIGH | Generated title:Samsung Mobile Devices Weaver Improper Access ControlImproper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. CWE-284Aug 10, 2026 | CVSS7.0v4.0 | EPSS0.113% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21063MEDIUM | Generated title:Samsung Mobile Devices AppLock Improper Export of Android Application ComponentsImproper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. CWE-926Aug 10, 2026 | CVSS6.8v4.0 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21062MEDIUM | Generated title:Samsung Mobile Devices SemClipboardService Authorization BypassAuthorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. CWE-939Aug 10, 2026 | CVSS4.8v4.0 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21061MEDIUM | Generated title:Samsung Dialer Improper Input ValidationImproper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability. CWE-20Aug 10, 2026 | CVSS6.0v4.0 | EPSS0.332% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21060MEDIUM | Generated title:Samsung Contacts Improper Input Validation Leading to Cross-Profile Data AccessImproper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. CWE-20Aug 10, 2026 | CVSS6.7v4.0 | EPSS0.154% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21059MEDIUM | Generated title:Samsung Contacts Improper Export of Android Application ComponentsImproper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. CWE-926Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.113% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21058MEDIUM | Generated title:Samsung Contacts Improper Input Validation Local Arbitrary File DeletionImproper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. CWE-20Aug 10, 2026 | CVSS6.9v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21047HIGH | Generated title:Samsung ImsService Out-of-Bounds Write Remote Code ExecutionOut-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code. CWE-787Jul 28, 2026 | CVSS8.3v4.0 | EPSS0.396% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21052MEDIUM | Generated title:Samsung SemClipboardService Path Traversal VulnerabilityPath traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege. CWE-22Jul 10, 2026 | CVSS6.8v4.0 | EPSS0.131% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21051MEDIUM | Generated title:Samsung Mobile Devices WLAN Security Incorrect Default PermissionsIncorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings. CWE-276Jul 10, 2026 | CVSS5.1v4.0 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21050MEDIUM | Generated title:Samsung SmartThingsKit Improper Access Control Information DisclosureImproper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. CWE-284Jul 10, 2026 | CVSS5.1v4.0 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21049HIGH | Generated title:Samsung libpadm.so Out-of-Bounds Write Local Privilege EscalationOut-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code. CWE-787Jul 10, 2026 | CVSS8.4v4.0 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21048HIGH | Generated title:Samsung libimagecodec.media.quram.so DNG Parsing Out-of-Bounds WriteOut-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory. CWE-787Jul 10, 2026 | CVSS8.4v4.0 | EPSS0.387% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21046HIGH | Generated title:Samsung fabricKeymaster Trustlet TOCTOU Race ConditionTime-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code. CWE-367Jul 10, 2026 | CVSS8.4v4.0 | EPSS0.096% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21045HIGH | Generated title:Samsung libimagecodec.media.quram.so TIFF Parsing Out-of-Bounds WriteOut-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory. CWE-787Jul 10, 2026 | CVSS8.4v4.0 | EPSS0.465% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21044MEDIUM | Generated title:Samsung KnoxGuardManager Improper AuthorizationImproper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. CWE-269Jul 10, 2026 | CVSS5.8v4.0 | EPSS0.096% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |