5.2
CVE-2026-20974 - Physical Attack Can Bypass Carrier Lock via Improper Network Restriction Input Validation
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
5.3
CVE-2026-20973 - OutβofβBounds Read in Samsung Android Image Codec Enables Remote Memory Disclosure
Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.
4.8
CVE-2026-20972 - Local Attack Can Enable Ultra Wideband on Samsung Android Devices
Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.
7.3
CVE-2026-20971 - Use After Free in PROCA Driver Enables Local Code Execution
Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.
6.8
CVE-2026-20970 - Improper Access Control in Samsung Android SLocation Service Enables Local Privilege Escalation
Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.
2.3
CVE-2026-20969 - Local Privilege Escalation through Improper SecSettings Validation
Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.
6.7
CVE-2026-20968 - Useβafterβfree in DualDAR allows local privileged code execution
Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.
6.8
CVE-2025-14803 - Nex-Forms Express WP Form Builder < 9.1.8 - Authenticated Stored XSS
The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.
4.3
CVE-2025-13749 - Clearfy <= 2.4.0 - Cross-Site Request Forgery to Update Notification Tampering
The Clearfy Cache β WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing nonce validation on the "wbcr_upm_change_flag" function. This makes it possible for unβ¦
5.3
CVE-2025-14886 - Japanized for WooCommerce <= 2.7.17 - Missing Authorization to Unauthenticated Order Status Modificβ¦
The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `order` REST API endpoint in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to mark any WooCommerce order aβ¦