Skip to main content

CWE archive

CWE-926 CVEs

Programmatic archive

90 CVEs tagged with CWE-9260 Critical, 9 High, 36 Medium, 45 Low, 0 Unrated.

CVE-2026-21081

Published Aug 10, 2026

Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is requ…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-21063

Published Aug 10, 2026

Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-21059

Published Aug 10, 2026

Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47363

Published Aug 7, 2026

In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from I…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-47361

Published Aug 7, 2026

In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conver…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-44965

Published Aug 7, 2026

In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWi…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-18604

Published Aug 3, 2026

A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such man…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-20470

Published Aug 3, 2026

In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges…

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-57848

Published Jul 18, 2026

Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts th…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-12960

Published Jul 3, 2026

An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
15.9
Public PoC observed

CVE-2026-54318

Published Jun 23, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with n…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-68713

Published Jun 15, 2026

An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no per…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44279

Published May 12, 2026

An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all ve…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3291

Published May 6, 2026

Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-15464

Published Jan 8, 2026

Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-14517

Published Dec 11, 2025

A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity  of the file AndroidManifest.xml. Executing manipulation can lead to improper expo…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2025-10722

Published Sep 19, 2025

A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file AndroidManifest.xml of the component com.dw.android.mukbee. The…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-10721

Published Sep 19, 2025

A vulnerability was determined in Webull Investing & Trading App 11.2.5.63 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml. This manipulation c…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-10718

Published Sep 19, 2025

A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the component com.ooma.office2. The manipulation results in imp…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2025-10717

Published Sep 19, 2025

A vulnerability has been found in intsig CamScanner App 6.91.1.5.250711 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the com…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-10716

Published Sep 19, 2025

A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2025-10715

Published Sep 19, 2025

A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an unknown function of the file AndroidManifest.xml of the com…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-10195

Published Sep 10, 2025

A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.seismic.doccenter. Such manipu…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-5500

Published Sep 9, 2025

A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.xiaoxun.xunoversea.mib…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-32347

Published Sep 4, 2025

In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of p…

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 90 CVEsPage 1 of 4