Galaxy store
This hub aggregates every CVE we track for Galaxy store, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
31
CVEs tracked
0
Critical
12
High
0
In CISA KEV
Severity distribution
MEDIUM18HIGH12LOW1
Monthly trend
0
0
0
0
1
0
1
0
0
0
0
1
0
0
1
1
0
3
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Galaxy store.
- CVE-2026-21002Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.5.5
- CVE-2026-21001Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.5.5
- CVE-2026-21000Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.5.5
- CVE-2026-20976Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.7.8
- CVE-2025-58483Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store.5.9
- CVE-2023-21483Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.6.4
- CVE-2025-20951Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.5.1
- CVE-2025-20895Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.3.2
- CVE-2024-34601Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore.5.9
- CVE-2024-20870Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.5.1
- CVE-2024-20825Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.5.5
- CVE-2024-20824Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.5.5
- CVE-2024-20823Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.5.5
- CVE-2024-20822Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.5.5
- CVE-2023-42581Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.7.5
Product normalization is registry-driven with AI assist and human review. How it works