Vulnerabilities
Summary — last 7 days
New vulnerabilities2,635▼ 213 vs. last week
Critical / high1,376▲ 145 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)81▼ 449 vs. last week
14 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.8) | 0.14% | — | Samsung KnoxguardmanagerAI | 7/10/2026 | 7/10/2026 | Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. | |
| Modified | Medium (6.1) | 2.6% | — | Apache Knox | 1/17/2022 | 6/17/2026 | When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by an attacker. This URL would need to be presented to the user… | |
| Modified | High (7.5) | 0.92% | — | Samsung Knox Cloud Services | 7/8/2021 | 6/17/2026 | Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication. | |
| Modified | Medium (4.3) | 0.36% | — | Samsung Knox | 2/10/2020 | 6/17/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this vulnerability. The specific flaws exists within… | |
| Modified | Medium (5.9) | 0.88% | — | Samsung Knox Enterprise Mobility ManagementSamsung Knox Identity Access Management | 2/20/2018 | 6/17/2026 | In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain… | |
| Modified | Medium (6.8) | 0.75% | — | Apache Knox | 5/26/2017 | 6/17/2026 | For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this activity is audit logged and can be easily associated with… | |
| Modified | Medium (5.5) | 1.2% | — | Samsung Knox | 1/27/2017 | 6/17/2026 | ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KNOX clipboard data via a crafted application. | |
| Modified | Medium (5.5) | 0.38% | — | Samsung Knox | 1/27/2017 | 6/17/2026 | Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service. | |
| Modified | Medium (4.7) | 0.44% | — | Samsung Knox | 1/27/2017 | 6/17/2026 | Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack. | |
| Modified | High (10) | 65% | — | Knox Software Arkeia Server Backup | 5/2/2005 | 6/16/2026 | Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request. | |
| Modified | High (10) | 2.2% | — | Knox Software Arkeia | 8/31/2001 | 6/16/2026 | Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges. | |
| Modified | High (7.2) | 0.35% | — | Knox Software Arkeia | 7/23/2001 | 6/16/2026 | Arkeia backup server 4.2.8-2 and earlier creates its database files with world-writable permissions, which could allow local users to overwrite the files or obtain sensitive information. | |
| Modified | Medium (5) | 1.3% | — | Knox Software Arkeia | 9/26/1999 | 6/16/2026 | Arkiea nlservd allows remote attackers to conduct a denial of service. | |
| Modified | High (7.2) | 1.1% | — | Knox Software Arkeia | 9/23/1999 | 6/16/2026 | Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable. |