Vulnerabilities

Summary — last 7 days

New vulnerabilities2,635▼ 213 vs. last week
Critical / high1,376▲ 145 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)81▼ 449 vs. last week
–

14 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.8)0.14%—Samsung KnoxguardmanagerAI7/10/20267/10/2026
Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.
ModifiedMedium (6.1)2.6%—Apache Knox1/17/20226/17/2026
When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by an attacker. This URL would need to be presented to the user…
ModifiedHigh (7.5)0.92%—Samsung Knox Cloud Services7/8/20216/17/2026
Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication.
ModifiedMedium (4.3)0.36%—Samsung Knox2/10/20206/17/2026
This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this vulnerability. The specific flaws exists within…
ModifiedMedium (5.9)0.88%—Samsung Knox Enterprise Mobility ManagementSamsung Knox Identity Access Management2/20/20186/17/2026
In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain…
ModifiedMedium (6.8)0.75%—Apache Knox5/26/20176/17/2026
For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this activity is audit logged and can be easily associated with…
ModifiedMedium (5.5)1.2%—Samsung Knox1/27/20176/17/2026
ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KNOX clipboard data via a crafted application.
ModifiedMedium (5.5)0.38%—Samsung Knox1/27/20176/17/2026
Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service.
ModifiedMedium (4.7)0.44%—Samsung Knox1/27/20176/17/2026
Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack.
ModifiedHigh (10)65%—Knox Software Arkeia Server Backup5/2/20056/16/2026
Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.
ModifiedHigh (10)2.2%—Knox Software Arkeia8/31/20016/16/2026
Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges.
ModifiedHigh (7.2)0.35%—Knox Software Arkeia7/23/20016/16/2026
Arkeia backup server 4.2.8-2 and earlier creates its database files with world-writable permissions, which could allow local users to overwrite the files or obtain sensitive information.
ModifiedMedium (5)1.3%—Knox Software Arkeia9/26/19996/16/2026
Arkiea nlservd allows remote attackers to conduct a denial of service.
ModifiedHigh (7.2)1.1%—Knox Software Arkeia9/23/19996/16/2026
Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable.