2

CVSS4.0

CVE-2026-4217 - XREAL Nebula App ai.nreal.nebula.universal CloudStoragePlugin.java credentials storage

A security vulnerability has been detected in XREAL Nebula App up to 3.2.1 on Android. This impacts an unknown function of the file inΒ ai/nreal/nebula/flutterPlugin/CloudStoragePlugin.java of the component ai.nreal.nebula.universal. Such manipulation of the argument accessKey/secretAccessKey/securi…

πŸ“… Published: March 16, 2026, 5:02 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

4.8

CVSS4.0

CVE-2026-4216 - i-SENS SmartLog App air.SmartLog.android hard-coded credentials

A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the component air.SmartLog.android. This manipulation causes hard-coded credentials. The attack can only be executed locally. The exploit has been made available to the public and could…

πŸ“… Published: March 16, 2026, 5:02 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

7.1

CVSS4.0

CVE-2026-21005 - Smart Switch Path Traversal Allowing Arbitrary File Overwrite

Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.

πŸ“… Published: March 16, 2026, 4:35 a.m. πŸ”„ Last Modified: April 2, 2026, 8 a.m.

6.9

CVSS4.0

CVE-2026-21004 - Improper Authentication in Smart Switch Enables Denial of Service

Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.

πŸ“… Published: March 16, 2026, 4:35 a.m. πŸ”„ Last Modified: April 2, 2026, 8 a.m.

5.3

CVSS4.0

CVE-2026-4215 - FlowCI flow-core-x SMTP Host ConfigServiceImpl.java save server-side request forgery

A security flaw has been discovered in FlowCI flow-core-x up to 1.23.01. The impacted element is the function Save of the file core/src/main/java/com/flowci/core/config/service/ConfigServiceImpl.java of the component SMTP Host Handler. The manipulation results in server-side request forgery. The at…

πŸ“… Published: March 16, 2026, 4:32 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

5.9

CVSS4.0

CVE-2026-21002 - Galaxy Store Improper Signature Verification Enabling Arbitrary App Installation

Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.

πŸ“… Published: March 16, 2026, 4:32 a.m. πŸ”„ Last Modified: April 9, 2026, 8:29 a.m.

8.7

CVSS4.0

CVE-2026-4214 - D-Link DNS-1550-04 app_mgr.cgi UPnP_AV_Server_Path_Setting stack-based overflow

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function UPnP_AV_Server_P…

πŸ“… Published: March 16, 2026, 4:32 a.m. πŸ”„ Last Modified: March 24, 2026, 10:45 a.m.

5.9

CVSS4.0

CVE-2026-21001 - Local File Write via Path Traversal in Samsung Galaxy Store

Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

πŸ“… Published: March 16, 2026, 4:32 a.m. πŸ”„ Last Modified: April 9, 2026, 8:29 a.m.

7

CVSS4.0

CVE-2026-21000 - Local File Creation via Improper Access Control in Samsung Galaxy Store

Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

πŸ“… Published: March 16, 2026, 4:32 a.m. πŸ”„ Last Modified: April 9, 2026, 8:29 a.m.

7.1

CVSS4.0

CVE-2026-20999 - Authentication Bypass via Replay Attack in Samsung Smart Switch Allowing Remote Privilege Escalation

Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.

πŸ“… Published: March 16, 2026, 4:32 a.m. πŸ”„ Last Modified: April 2, 2026, 8 a.m.
Total resulsts: 349182
Page 1104 of 34,919
Β« previous page Β» next page
Filters