Samsung
4,624 known vulnerabilities
Top Products
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local a
Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.
Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access
Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ
A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to int
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart d
Unprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch arbitrary activity.
PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without
Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely
Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files
DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arb
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of co
Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local atta
Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local a
Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored cr
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email
Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing scri
Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of co
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_tok
Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an
Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an u
Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access
Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary priv
Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authen
Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to
DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary
Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to ove
Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The pat
Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interacti
Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version
Improper access control vulnerability in Samsung Security Supporter prior to version 1.2.40.0 allows attacker to set the
Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute cal
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications
Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file withou
Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allow
Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access priv
Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute a
DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.
DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.
Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that i
Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbit
Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to acce
Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with s
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Androi
Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows a
Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.
A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escala
Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access pa
Frequently Asked Questions
How many CVEs affect Samsung?
Samsung has 4,624 CVE records in our database, including 376 critical and 1561 high severity vulnerabilities. 15 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Samsung vulnerabilities?
Samsung has 376 critical severity (CVSS 9.0+) and 1561 high severity (CVSS 7.0-8.9) vulnerabilities. 15 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Samsung vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Samsung products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Samsung Vulnerabilities
CyberStrike scans your infrastructure for Samsung vulnerabilities and provides real-time remediation guidance.
Get Started