5.1
CVE-2026-20976 - Local Script Execution via Improper Input Validation in Galaxy Store
Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.
2.1
CVE-2026-20975 - Local Permission Escalation in Samsung Cloud Allows Access to Arbitrary Files
Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.
5.2
CVE-2026-20974 - Physical Attack Can Bypass Carrier Lock via Improper Network Restriction Input Validation
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
5.3
CVE-2026-20973 - OutβofβBounds Read in Samsung Android Image Codec Enables Remote Memory Disclosure
Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.
4.8
CVE-2026-20972 - Local Attack Can Enable Ultra Wideband on Samsung Android Devices
Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.
7.3
CVE-2026-20971 - Use After Free in PROCA Driver Enables Local Code Execution
Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.
6.8
CVE-2026-20970 - Improper Access Control in Samsung Android SLocation Service Enables Local Privilege Escalation
Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.
2.3
CVE-2026-20969 - Local Privilege Escalation through Improper SecSettings Validation
Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.
6.7
CVE-2026-20968 - Useβafterβfree in DualDAR allows local privileged code execution
Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.
6.8
CVE-2025-14803 - Nex-Forms Express WP Form Builder < 9.1.8 - Authenticated Stored XSS
The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.