Vulnerabilities
Summary — last 7 days
New vulnerabilities2,685▼ 177 vs. last week
Critical / high1,223▼ 305 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 186 vs. last week
1,690 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (4.8) | 0.11% | — | Samsung Android | 9/9/2026 | 9/28/2026 | Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration. | |
| Deferred | Medium (6.2) | 0.17% | — | Samsung EscargotAI | 9/7/2026 | 9/28/2026 | An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry count exceeds UINT16_MAX. This issue affects… | |
| Deferred | Medium (6.2) | 0.18% | — | Samsung WalrusAI | 9/7/2026 | 9/28/2026 | Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check.… | |
| Deferred | High (7.8) | 0.17% | — | Samsung WalrusAI | 9/7/2026 | 9/28/2026 | Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7. | |
| Deferred | Medium (4.4) | 0.15% | — | Samsung RlottieAI | 9/4/2026 | 9/8/2026 | Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630. | |
| Deferred | Medium (6.3) | 0.13% | — | Samsung TizenfxAI | 9/3/2026 | 9/8/2026 | Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers. | |
| Deferred | Medium (5.5) | 0.11% | — | Samsung MtowerAI | 9/1/2026 | 9/1/2026 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be. | |
| Deferred | Medium (5.5) | 0.15% | — | Samsung MtowerAI | 9/1/2026 | 9/1/2026 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e. | |
| Deferred | Medium (5.5) | 0.15% | — | Samsung MtowerAI | 9/1/2026 | 9/1/2026 | NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a. | |
| Deferred | Medium (5.5) | 0.15% | — | Samsung RlottieAI | 8/31/2026 | 9/1/2026 | Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51. | |
| Analyzed | Medium (6.5) | 0.35% | — | Samsung Rlottie | 8/12/2026 | 9/30/2026 | Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. | |
| Analyzed | Medium (6.5) | 0.36% | — | Samsung Rlottie | 8/12/2026 | 9/30/2026 | Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation. | |
| Analyzed | Medium (6.5) | 0.36% | — | Samsung Rlottie | 8/11/2026 | 9/23/2026 | Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation. | |
| Analyzed | Medium (6.5) | 0.36% | — | Samsung Rlottie | 8/11/2026 | 9/23/2026 | Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation. | |
| Awaiting Analysis | Medium (6.9) | 0.13% | — | Samsung SmartthingsAI | 8/10/2026 | 8/18/2026 | Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. | |
| Analyzed | Medium (6.8) | 0.26% | — | Samsung Smart Switch | 8/10/2026 | 8/19/2026 | Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | |
| Analyzed | Medium (6.9) | 0.17% | — | Samsung Health | 8/10/2026 | 8/19/2026 | Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. | |
| Awaiting Analysis | Medium (5.1) | 0.13% | — | Samsung Pass AutofillAI | 8/10/2026 | 8/18/2026 | Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | |
| Analyzed | Medium (6.9) | 0.17% | — | Samsung Smart Switch | 8/10/2026 | 8/19/2026 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | |
| Analyzed | High (7) | 0.10% | — | Samsung Smart Switch | 8/10/2026 | 8/19/2026 | Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data. | |
| Analyzed | Medium (4.7) | 0.16% | — | Samsung Smart Switch | 8/10/2026 | 8/19/2026 | Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity. | |
| Analyzed | Medium (6.9) | 0.13% | — | Samsung Health | 8/10/2026 | 8/19/2026 | Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. | |
| Analyzed | Medium (6.9) | 0.13% | — | Samsung Health | 8/10/2026 | 8/19/2026 | Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. | |
| Awaiting Analysis | High (7.2) | 0.14% | — | Samsung BixbyAI | 8/10/2026 | 8/18/2026 | Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege. | |
| Analyzed | Medium (5.2) | 0.21% | — | Samsung Android | 8/10/2026 | 8/19/2026 | Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. |