๐จ CVE-2026-21067
Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
๐@cveNotify
Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
๐@cveNotify
๐จ CVE-2026-21068
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.
๐@cveNotify
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.
๐@cveNotify
๐จ CVE-2026-21069
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
๐@cveNotify
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
๐@cveNotify
๐จ CVE-2026-21071
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
๐@cveNotify
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
๐@cveNotify
๐จ CVE-2026-21072
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
๐@cveNotify
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
๐@cveNotify
๐จ CVE-2026-21073
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
๐@cveNotify
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
๐@cveNotify
๐จ CVE-2026-21074
Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.
๐@cveNotify
Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.
๐@cveNotify
๐จ CVE-2026-21075
Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
๐@cveNotify
Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
๐@cveNotify
๐จ CVE-2026-21076
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
๐@cveNotify
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
๐@cveNotify
๐จ CVE-2026-21077
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
๐@cveNotify
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
๐@cveNotify
๐จ CVE-2026-21078
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.
๐@cveNotify
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.
๐@cveNotify
๐จ CVE-2026-21079
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.
๐@cveNotify
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.
๐@cveNotify
๐จ CVE-2026-21080
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
๐@cveNotify
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
๐@cveNotify
๐จ CVE-2026-21081
Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
๐@cveNotify
Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
๐@cveNotify
๐จ CVE-2026-21082
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
๐@cveNotify
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
๐@cveNotify
๐จ CVE-2026-21083
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
๐@cveNotify
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
๐@cveNotify
๐จ CVE-2026-21084
Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.
๐@cveNotify
Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.
๐@cveNotify
๐จ CVE-2026-18503
Attacker-controlled CSV samples can trigger super-linear
regular-expression work during dialect sniffing and consume significant
CPU when applications pass unbounded input to csv.Sniffer.sniff().
๐@cveNotify
Attacker-controlled CSV samples can trigger super-linear
regular-expression work during dialect sniffing and consume significant
CPU when applications pass unbounded input to csv.Sniffer.sniff().
๐@cveNotify
GitHub
[3.12] gh-98820: Fix quadratic time in csv.Sniffer for quoted fields โฆ ยท python/cpython@063d455
โฆ(GH-154867) (#155166)
(cherry picked from commit b30c7fa9edd921a118f286e9f90f560777fa693b)
Co-authored-by: Miss Islington (bot) <31488909+miss-islington@users.noreply.github.com>
(cherry picked from commit b30c7fa9edd921a118f286e9f90f560777fa693b)
Co-authored-by: Miss Islington (bot) <31488909+miss-islington@users.noreply.github.com>
๐จ CVE-2026-12339
A Zip Slip vulnerability in the WebUI ISP
Upgrade functionality allows arbitrary file write via a crafted archive
containing directory traversal sequences. An authenticated administrator may
overwrite arbitrary files on the system.Successful
exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
๐@cveNotify
A Zip Slip vulnerability in the WebUI ISP
Upgrade functionality allows arbitrary file write via a crafted archive
containing directory traversal sequences. An authenticated administrator may
overwrite arbitrary files on the system.Successful
exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
๐@cveNotify
TP-Link
Download for Archer MR200 | TP-Link
TP Link - Download Center Detail
๐จ CVE-2025-30237
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication
checks are not consistently enforced on certain endpoints. An attacker can send
specially crafted requests to bypass authentication and directly invoke
privileged functionality without valid credentials. This issue arises from
improper enforcement of access control mechanisms on sensitive operations.
Successful
exploitation may allow an unauthenticated attacker to execute privileged
operations and gain full control of the device.
๐@cveNotify
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication
checks are not consistently enforced on certain endpoints. An attacker can send
specially crafted requests to bypass authentication and directly invoke
privileged functionality without valid credentials. This issue arises from
improper enforcement of access control mechanisms on sensitive operations.
Successful
exploitation may allow an unauthenticated attacker to execute privileged
operations and gain full control of the device.
๐@cveNotify
๐จ CVE-2025-30238
In affected TP-Link Aginet devices, insufficient
authorization validation allows authenticated low-privileged users to execute higher-privileged
operations.
An attacker
may perform administrative actions such as creating privileged accounts or
modifying critical configuration settings.
๐@cveNotify
In affected TP-Link Aginet devices, insufficient
authorization validation allows authenticated low-privileged users to execute higher-privileged
operations.
An attacker
may perform administrative actions such as creating privileged accounts or
modifying critical configuration settings.
๐@cveNotify