Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In September 2025
Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.
CVSS Score
4.0
EPSS Score
0.001
Published
2025-09-03
Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.
CVSS Score
6.8
EPSS Score
0.001
Published
2025-09-03
Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.
CVSS Score
4.0
EPSS Score
0.001
Published
2025-09-03
Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.
CVSS Score
5.1
EPSS Score
0.001
Published
2025-09-03
Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
CVSS Score
5.5
EPSS Score
0.001
Published
2025-09-03
Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.
CVSS Score
6.4
EPSS Score
0.001
Published
2025-09-03
The Sticky Side Buttons WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVSS Score
3.3
EPSS Score
0.002
Published
2025-09-03
Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.
CVSS Score
5.1
EPSS Score
0.001
Published
2025-09-03
Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.
CVSS Score
8.5
EPSS Score
0.001
Published
2025-09-03
Improper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitive information.
CVSS Score
5.4
EPSS Score
0.003
Published
2025-09-03


Contact Us

Shodan ® - All rights reserved