Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-20996

7.1

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.

Samsung
Details

CVE-2026-20995

5.3

Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.

Exposure
Details

CVE-2026-20994

7.0

URL redirection in Samsung Account prior to version 15.5.01.1 allows remote attackers to potentially get access token.

Samsung
Details

CVE-2026-20993

4.8

Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information.

Samsung
Details

CVE-2026-20992

4.8

Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.

Samsung
Details

CVE-2026-20991

6.7

Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.

Samsung
Details

CVE-2026-20990

8.4

Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege.

Samsung
Details

CVE-2026-20989

5.1

Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.

Samsung
Details

CVE-2026-20988

6.8

Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for …

Samsung
Details

CVE-2026-1948

4.3

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function in all …

WordPress
Details
639/3864