Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Samsung

4,624 known vulnerabilities

95
CRITICAL
401
HIGH
944
MEDIUM
115
LOW

Top Products

android 491 exynos 980 121 exynos 1380 firmware 118 exynos 1380 117 exynos 1280 firmware 116 exynos 1280 116 exynos 980 firmware 109 exynos 850 firmware 96 exynos 850 95 exynos 1080 firmware 95
1,555 CVEs · Page 9/32
7.5
CVE-2024-52923

An issue was discovered in NRMM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990,

5.5
CVE-2025-20933

Out-of-bounds read in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-o

5.5
CVE-2025-20932

Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻rea

7.3
CVE-2025-20931

Out-of-bounds write in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to execute a

5.5
CVE-2025-20930

Out-of-bounds read in parsing jpeg image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-

7.3
CVE-2025-20929

Out-of-bounds write in parsing jpeg image in Samsung Notes prior to version 4.4.26.71 allows local attackers to execute

5.5
CVE-2025-20928

Out-of-bounds read in parsing wbmp image in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access o

5.5
CVE-2025-20927

Out-of-bounds read in parsing image data in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access o

5.5
CVE-2025-20926

Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local atta

5.5
CVE-2025-20925

Out-of-bounds read in applying binary of text data in Samsung Notes prior to version 4.4.26.71 allows local attackers to

4.6
CVE-2025-20924

Improper access control in Samsung Notes prior to version 4.4.26.71 allows physical attackers to access data across mult

5.5
CVE-2025-20922

Out-of-bounds read in appending text paragraph in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-

5.5
CVE-2025-20921

Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.26.71 allows attackers to re

5.5
CVE-2025-20920

Out-of-bounds read in action link data in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bound

5.5
CVE-2025-20919

Out-of-bounds read in applying binary of video content in Samsung Notes prior to version 4.4.26.71 allows attackers to r

5.5
CVE-2025-20918

Out-of-bounds read in applying extra data of base content in Samsung Notes prior to version 4.4.26.71 allows attackers t

5.5
CVE-2025-20917

Out-of-bounds read in applying binary of pdf content in Samsung Notes prior to version 4.4.26.71 allows attackers to rea

5.5
CVE-2025-20916

Out-of-bounds read in reading string of SPen in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of

5.5
CVE-2025-20915

Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to r

5.5
CVE-2025-20914

Out-of-bounds read in applying binary of hand writing content in Samsung Notes prior to version 4.4.26.71 allows attacke

5.5
CVE-2025-20913

Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to

6.2
CVE-2025-20912

Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data withi

4.4
CVE-2025-20911

Improper access control in sem_wifi service prior to SMR Mar-2025 Release 1 allows privileged local attackers to update

6.2
CVE-2025-20910

Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access da

4.0
CVE-2025-20909

Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to

6.5
CVE-2025-20908

Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Aura

7.3
CVE-2025-20903

Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch priv

7.5
CVE-2024-46923

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a

7.5
CVE-2024-46922

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The absence of a null check leads to a Denial

6.0
CVE-2025-20907

Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disab

6.3
CVE-2025-20905

Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to r

6.3
CVE-2025-20904

Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memo

4.4
CVE-2025-20901

Out-of-bounds read in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to read out-of-bou

6.3
CVE-2025-20900

Out-of-bounds write in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to write out-of-b

4.6
CVE-2025-20898

Improper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across

4.0
CVE-2025-20896

Use of implicit intent for sensitive communication in EasySetup prior to version 11.1.18 allows local attackers to acces

3.2
CVE-2025-20895

Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to ins

4.6
CVE-2025-20894

Improper access control in Samsung Email prior to version 6.1.97.1 allows physical attackers to access data across multi

5.1
CVE-2025-20893

Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the conf

5.9
CVE-2025-20892

Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute

5.3
CVE-2025-20891

Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 a

7.0
CVE-2025-20890

Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to e

5.3
CVE-2025-20889

Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows lo

7.0
CVE-2025-20888

Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local

5.3
CVE-2025-20887

Out-of-bounds read in accessing table used for svp8t in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attack

4.1
CVE-2025-20886

Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privile

6.4
CVE-2025-20885

Out-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to cause memor

4.6
CVE-2025-20884

Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data acro

4.6
CVE-2025-20883

Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across m

7.0
CVE-2025-20882

Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows

Frequently Asked Questions

How many CVEs affect Samsung?

Samsung has 4,624 CVE records in our database, including 376 critical and 1561 high severity vulnerabilities. 15 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Samsung vulnerabilities?

Samsung has 376 critical severity (CVSS 9.0+) and 1561 high severity (CVSS 7.0-8.9) vulnerabilities. 15 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Samsung vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Samsung products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Samsung Vulnerabilities

CyberStrike scans your infrastructure for Samsung vulnerabilities and provides real-time remediation guidance.

Get Started