Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 25 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:Samsung SmartThings Improper Access Control Information Disclosure

Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.

CWE-284Aug 10, 2026
CVSS6.9v4.0EPSS0.091%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Smart Switch Improper Input Validation Leading to Sensitive Data Access

Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

CWE-20Aug 10, 2026
CVSS6.8v4.0EPSS0.153%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Health Relative Path Traversal Information Disclosure

Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

CWE-23Aug 10, 2026
CVSS6.9v4.0EPSS0.137%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:SamsungPassAutofill Improper Export of Android Application Components

Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

CWE-926Aug 10, 2026
CVSS5.1v4.0EPSS0.091%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Smart Switch Cleartext Storage of Sensitive Information

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

CWE-312Aug 10, 2026
CVSS6.9v4.0EPSS0.105%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Smart Switch Missing Encryption for Sensitive Data

Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.

CWE-311Aug 10, 2026
CVSS7.0v4.0EPSS0.065%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Smart Switch Insufficient Verification of Data Authenticity

Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.

CWE-345Aug 10, 2026
CVSS4.7v4.0EPSS0.097%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Health Incorrect Authorization Information Disclosure

Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

CWE-863Aug 10, 2026
CVSS6.9v4.0EPSS0.105%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Health Incorrect Authorization

Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

CWE-863Aug 10, 2026
CVSS6.9v4.0EPSS0.105%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung My Galaxy Custom URL Scheme Improper Authorization

Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.

CWE-939Aug 10, 2026
CVSS5.3v4.0EPSS0.36%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Bixby Incorrect Default Permissions Local Privilege Escalation

Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.

CWE-276Aug 10, 2026
CVSS7.2v4.0EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Galaxy Themes Improper Input Validation Vulnerability

Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.

CWE-20Aug 10, 2026
CVSS5.2v4.0EPSS0.155%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung libsavsvc.so VC1 Codec Out-of-Bounds Write

Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

CWE-20Aug 10, 2026
CVSS5.1v4.0EPSS0.119%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Mobile Devices libsavsvc.so MPEG4 Codec Out-of-Bounds Write

Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

CWE-20Aug 10, 2026
CVSS5.1v4.0EPSS0.111%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Mobile Devices Improper Input Validation in Samsung Message

Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.

CWE-20Aug 10, 2026
CVSS5.1v4.0EPSS0.145%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung libsavsvc.so VC1 Codec Out-of-Bounds Write

Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

CWE-681Aug 10, 2026
CVSS5.1v4.0EPSS0.111%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Mobile Devices libril_sem.so Stack-based Buffer Overflow

Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

CWE-121Aug 10, 2026
CVSS8.4v4.0EPSS0.127%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Mobile Devices libsmsd.so Out-of-Bounds Write

Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

CWE-20Aug 10, 2026
CVSS5.1v4.0EPSS0.119%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung libcodec2_sec_flacdec.so Improper Input Validation Leading to Out-of-Bounds Write

Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

CWE-20Aug 10, 2026
CVSS5.1v4.0EPSS0.119%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Mobile libcodec2secqcelpdec Out-of-Bounds Write

Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

CWE-20Aug 10, 2026
CVSS4.4v4.0EPSS0.106%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Mobile Devices Weaver Improper Access Control

Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.

CWE-284Aug 10, 2026
CVSS7.0v4.0EPSS0.113%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Mobile Devices AppLock Improper Export of Android Application Components

Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.

CWE-926Aug 10, 2026
CVSS6.8v4.0EPSS0.155%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Mobile Devices SemClipboardService Authorization Bypass

Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

CWE-939Aug 10, 2026
CVSS4.8v4.0EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Dialer Improper Input Validation

Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.

CWE-20Aug 10, 2026
CVSS6.0v4.0EPSS0.332%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Samsung Contacts Improper Input Validation Leading to Cross-Profile Data Access

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.

CWE-20Aug 10, 2026
CVSS6.7v4.0EPSS0.154%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX