Internet
Vendor:
First CVE: Mar 4, 2021 · Active for 5 years
29
Total CVEs
More Total CVEs than 96% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Internet over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2021
5 years ago
Most Recent CVE
Jun 5, 2026
49 days ago
CVE Severity & Scoring
Internet29 CVEs
10%
72%
17%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local14 (48.3%)
Network9 (31.0%)
Unknown0 (0.0%)
Physical6 (20.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (93.1%)
High2 (6.9%)
Unknown0 (0.0%)
User Interaction
None22 (75.9%)
Unknown0 (0.0%)
Required7 (24.1%)
Privileges Required
Low12 (41.4%)
High1 (3.4%)
None16 (55.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21036MEDIUM Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information. | Jun 5, 2026 | 5.5 | 25 | NO | NO |
CVE-2021-25400HIGH Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action. | Jun 11, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-25418HIGH Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition. | Jun 11, 2021 | 7.8 | 23 | NO | NO |
CVE-2025-58485MEDIUM Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script. | Dec 2, 2025 | 5.5 | 22 | NO | NO |
CVE-2022-22290MEDIUM Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page. | Jan 14, 2022 | 6.5 | 22 | NO | NO |
CVE-2025-20995HIGH Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to read and wri | Jun 4, 2025 | 7.1 | 21 | NO | NO |
CVE-2025-20994HIGH Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to access r | Jun 4, 2025 | 7.1 | 21 | NO | NO |
CVE-2024-20838HIGH Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code. | Mar 5, 2024 | 7.8 | 21 | NO | NO |
CVE-2021-25520MEDIUM Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes i | Dec 8, 2021 | 6.1 | 21 | NO | NO |
CVE-2022-22284MEDIUM Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication | Jan 10, 2022 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (29 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (29 CVEs).
Media Mentions
Signals from CVEs in this product scope (29 CVEs).
Top CNAs Publishing CVEs For Internet
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.9 | 1 | 5.9 | 0.3% | 0 | 0 |
| 24.0 | 1 | 5.3 | 0.4% | 0 | 0 |