Vendor CVEs
Samsung Pay
All CVEs
310 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-25525 | Low | 0.13 | 2.0 | 0.00 | Dec 8, 2021 | Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition. | ||
| CVE-2026-21057 | Med | 0.00 | — | 0.00 | Jul 10, 2026 | Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2026-21054 | Med | 0.00 | — | 0.00 | Jul 10, 2026 | Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data. | ||
| CVE-2026-21052 | Med | 0.00 | — | 0.00 | Jul 10, 2026 | Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege. | ||
| CVE-2026-21050 | Med | 0.00 | — | 0.00 | Jul 10, 2026 | Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2026-21046 | Hig | 0.00 | — | 0.00 | Jul 10, 2026 | Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code. | ||
| CVE-2026-21044 | Med | 0.00 | — | 0.00 | Jul 10, 2026 | Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. | ||
| CVE-2026-21041 | Med | 0.00 | — | 0.00 | Jul 10, 2026 | Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2026-21040 | Med | 0.00 | — | 0.00 | Jul 10, 2026 | Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs. | ||
| CVE-2026-21039 | Med | 0.00 | — | 0.00 | Jul 10, 2026 | Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings. |
- risk 0.13cvss 2.0epss 0.00
Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition.
- risk 0.00cvss —epss 0.00
Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory.
- risk 0.00cvss —epss 0.00
Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.
- risk 0.00cvss —epss 0.00
Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.
- risk 0.00cvss —epss 0.00
Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
- risk 0.00cvss —epss 0.00
Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code.
- risk 0.00cvss —epss 0.00
Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.
- risk 0.00cvss —epss 0.00
Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
- risk 0.00cvss —epss 0.00
Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs.
- risk 0.00cvss —epss 0.00
Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings.
Page 7 of 7