Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2024-7399 | Samsung | MagicINFO 9 Server | Samsung MagicINFO 9 Server Path Traversal Vulnerability Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority. | 8.8 CNA | 2026-04-24 | 2026-05-08 | Unknown |
| CVE-2025-21042 | Samsung | Mobile Devices | Samsung Mobile Devices Out-of-Bounds Write Vulnerability Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code. | 8.8 CNA | 2025-11-10 | 2025-12-01 | Unknown |
| CVE-2025-21043 | Samsung | Mobile Devices | Samsung Mobile Devices Out-of-Bounds Write Vulnerability Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code. | 8.8 CNA | 2025-10-02 | 2025-10-23 | Unknown |
| CVE-2025-4632 | Samsung | MagicINFO 9 Server | Samsung MagicINFO 9 Server Path Traversal Vulnerability Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority. | 9.8 CNA | 2025-05-22 | 2025-06-12 | Unknown |
| CVE-2022-22265 | Samsung | Mobile Devices | Samsung Mobile Devices Use-After-Free Vulnerability Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution. | 5.0 CNA | 2023-09-18 | 2023-10-09 | Unknown |
| CVE-2021-25372 | Samsung | Mobile Devices | Samsung Mobile Devices Improper Boundary Check Vulnerability Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access. | 6.1 CNA | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2021-25371 | Samsung | Mobile Devices | Samsung Mobile Devices Unspecified Vulnerability Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP. | 6.1 CNA | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2021-25395 | Samsung | Mobile Devices | Samsung Mobile Devices Race Condition Vulnerability Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. | 6.4 CNA | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2021-25394 | Samsung | Mobile Devices | Samsung Mobile Devices Race Condition Vulnerability Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. | 6.4 CNA | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2021-25489 | Samsung | Mobile Devices | Samsung Mobile Devices Improper Input Validation Vulnerability Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic. | 3.3 CNA | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2021-25487 | Samsung | Mobile Devices | Samsung Mobile Devices Out-of-Bounds Read Vulnerability Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer. | 7.3 CNA | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2023-21492 | Samsung | Mobile Devices | Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass. | 4.4 CNA | 2023-05-19 | 2023-06-09 | Unknown |
| CVE-2021-25370 | Samsung | Mobile Devices | Samsung Mobile Devices Memory Corruption Vulnerability Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369. | 6.1 CNA | 2022-11-08 | 2022-11-29 | Unknown |
| CVE-2021-25369 | Samsung | Mobile Devices | Samsung Mobile Devices Improper Access Control Vulnerability Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370. | 6.2 CNA | 2022-11-08 | 2022-11-29 | Unknown |
| CVE-2021-25337 | Samsung | Mobile Devices | Samsung Mobile Devices Improper Access Control Vulnerability Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370. | 4.4 CNA | 2022-11-08 | 2022-11-29 | Unknown |