Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 614

Количество 331 614

nvd логотип

CVE-2026-2105

2 дня назад

A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/deleteDept of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\DeptController.java of the component Department Management. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-2103

3 дня назад

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and database can decrypt all stored credentials.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-20987

6 дней назад

Improper input validation in GalaxyDiagnostics prior to version 3.5.050 allows local privileged attackers to execute privileged commands.

EPSS: Низкий
nvd логотип

CVE-2026-20986

6 дней назад

Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members.

EPSS: Низкий
nvd логотип

CVE-2026-20985

6 дней назад

Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.

EPSS: Низкий
nvd логотип

CVE-2026-20984

6 дней назад

Improper handling of insufficient permission in Galaxy Wearable installed on non-Samsung Device prior to version 2.2.68 allows local attackers to access sensitive information.

EPSS: Низкий
nvd логотип

CVE-2026-20983

6 дней назад

Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-20982

6 дней назад

Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.

CVSS3: 6
EPSS: Низкий
nvd логотип

CVE-2026-20981

6 дней назад

Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2026-20980

6 дней назад

Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2026-20979

6 дней назад

Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-20978

6 дней назад

Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-20977

6 дней назад

Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-20976

около 1 месяца назад

Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-20975

около 1 месяца назад

Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-20974

около 1 месяца назад

Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2026-20973

около 1 месяца назад

Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-20972

около 1 месяца назад

Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2026-20971

около 1 месяца назад

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-20970

около 1 месяца назад

Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-2105

A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/deleteDept of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\DeptController.java of the component Department Management. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 6.3
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-2103

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and database can decrypt all stored credentials.

CVSS3: 7.1
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-20987

Improper input validation in GalaxyDiagnostics prior to version 3.5.050 allows local privileged attackers to execute privileged commands.

0%
Низкий
6 дней назад
nvd логотип
CVE-2026-20986

Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members.

0%
Низкий
6 дней назад
nvd логотип
CVE-2026-20985

Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.

0%
Низкий
6 дней назад
nvd логотип
CVE-2026-20984

Improper handling of insufficient permission in Galaxy Wearable installed on non-Samsung Device prior to version 2.2.68 allows local attackers to access sensitive information.

0%
Низкий
6 дней назад
nvd логотип
CVE-2026-20983

Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege.

CVSS3: 7.8
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-20982

Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.

CVSS3: 6
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-20981

Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.

CVSS3: 6.6
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-20980

Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.

CVSS3: 6.8
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-20979

Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege.

CVSS3: 7.8
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-20978

Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.

CVSS3: 6.1
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-20977

Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.

CVSS3: 5.5
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-20976

Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-20975

Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.

CVSS3: 5.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-20974

Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.

CVSS3: 4.6
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-20973

Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-20972

Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-20971

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-20970

Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу