25 Total CVEs
25 AI Analyzed
1 CISA KEV
14 Critical

Profile

4% ended up actively exploited 1 of 25 added to CISA KEV
56% rated critical (CVSS 9.0+) 14 critical, 11 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

5 CVEs in the last 12 months

Products

  • MagicINFO1
  • MagicINFO 9 Server1

2 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-25 of 25 CVEs
CVE-2026-25203
Analyzed
7.8
Samsung Electronics MagicINFO

Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 2...

2026-04-10
CVE-2026-25202
Analyzed
9.8
Samsung Electronics Multiple Products

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects Ma...

2026-02-02
CVE-2026-25201
Analyzed
8.8
Samsung Electronics Multiple Products

An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server

2026-02-02
CVE-2026-25200
Analyzed
9.8
Samsung Electronics Multiple Products

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in a...

2026-02-02
CVE-2025-54455
Analyzed
9.1
Samsung Electronics Multiple Products

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Serv...

2025-07-23
CVE-2025-54454
Analyzed
9.1
Samsung Electronics Multiple Products

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Serv...

2025-07-23
CVE-2025-54453
Analyzed
8.8
Samsung Electronics Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inj...

2025-07-23
CVE-2025-54452
Analyzed
7.3
Samsung Electronics Multiple Products

Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass

2025-07-23
CVE-2025-54451
Analyzed
9.8
Samsung Electronics Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue aff...

2025-07-23
CVE-2025-54450
Analyzed
7.2
Samsung Electronics Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inj...

2025-07-23
CVE-2025-54449
Analyzed
9.8
Samsung Electronics Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magic...

2025-07-23
CVE-2025-54448
Analyzed
9.8
Samsung Electronics Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magic...

2025-07-23
CVE-2025-54447
Analyzed
8.1
Samsung Electronics Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection

2025-07-23
CVE-2025-54446
Analyzed
9.8
Samsung Electronics Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a...

2025-07-23
CVE-2025-54445
Analyzed
8.2
Samsung Electronics Multiple Products

Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery

2025-07-23
CVE-2025-54444
Analyzed
9.8
Samsung Electronics Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magic...

2025-07-23
CVE-2025-54443
Analyzed
9.8
Samsung Electronics Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a...

2025-07-23
CVE-2025-54442
Analyzed
9.8
Samsung Electronics Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magic...

2025-07-23
CVE-2025-54441
Analyzed
8.8
Samsung Electronics Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection

2025-07-23
CVE-2025-54440
Analyzed
9.8
Samsung Electronics Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magic...

2025-07-23
CVE-2025-54439
Analyzed
8.8
Samsung Electronics Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection

2025-07-23
CVE-2025-54438
Analyzed
9.8
Samsung Electronics Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a...

2025-07-23
CVE-2025-53080
Analyzed
7.1
Samsung Electronics Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers t...

2025-07-29
CVE-2025-53078
Analyzed
8
Samsung Electronics Multiple Products

Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system

2025-07-29
CVE-2024-7399
KEV Analyzed
9.5
Samsung Electronics MagicINFO 9 Server

Samsung MagicINFO 9 Server Path Traversal Vulnerability - Active in CISA KEV catalog.

2026-04-25