Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-21073 — Samsung Galaxy Themes Improper Input Validation Vulnerability

Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.

android | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.8 HIGH
CVE-2026-21072 — libsavsvc VC1 Codec Out-of-Bounds Memory Write Vulnerability

Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

android | Memory Corruption
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.8 HIGH
CVE-2026-21071 — Samsung libsavsvc MPEG4 Codec Out-of-Bounds Memory Write

Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

android | Memory Corruption
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
5.1 MEDIUM
CVE-2026-21070 — Samsung Message Improper Input Validation Vulnerability

Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.

android | Information Disclosure
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.8 HIGH
CVE-2026-21069 — libsavsvc VC1 Codec Out-of-Bounds Memory Write via Integer Conversion Error

Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

android | Memory Corruption
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
8.4 HIGH
CVE-2026-21068 — Samsung libril_sem.so Stack-based Buffer Overflow

Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

android | Memory Corruption
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.8 HIGH
CVE-2026-21067 — libsmsd Out-of-Bounds Memory Write

Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

android | Memory Corruption
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.8 HIGH
CVE-2026-21066 — libcodec2_sec_flacdec Out-of-Bounds Write

Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

android | Memory Corruption
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.8 HIGH
CVE-2026-21065 — Samsung libcodec2secqcelpdec Out-of-Bounds Write

Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

android | Memory Corruption
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.0 HIGH
CVE-2026-21064 — Weaver Improper Access Control Vulnerability

Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.

android | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
6.8 MEDIUM
CVE-2026-21063 — AppLock Improper Component Export Vulnerability

Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.

android | Authentication
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-64940 — Nishishi Factory Tegalog Authentication Bypass Vulnerability

Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log…

| Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
6.8 MEDIUM
CVE-2026-57279 — Cybozu Garoon Cross-Site Scripting Vulnerability

Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product.

garoon | Cross-Site Scripting
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
4.8 MEDIUM
CVE-2026-21062 — SemClipboardService Authorization Bypass

Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

android | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
6.5 MEDIUM
CVE-2026-21061 — Samsung Dialer Improper Input Validation Vulnerability

Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.

android | Remote | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
6.7 MEDIUM
CVE-2026-21060 — Samsung Contacts Cross-Profile Data Access Vulnerability

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.

android | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.1 HIGH
CVE-2026-21059 — Samsung Contacts Improper Component Export Arbitrary File Deletion Vulnerability

Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

android | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.1 HIGH
CVE-2026-21058 — Samsung Contacts Arbitrary File Deletion Vulnerability

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

android | Path Traversal
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
9.8 CRITICAL
CVE-2026-19089 — Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload

The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as a…

Remote | Misconfiguration
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
6.5 MEDIUM
CVE-2026-19077 — Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Le…

The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Dup…

Remote | Authorization
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
Showing 20 of 13948 Results