Skip to main content

CWE archive

CWE-926 CVEs

Programmatic archive

82 CVEs tagged with CWE-9260 Critical, 9 High, 29 Medium, 44 Low, 0 Unrated.

CVE-2026-57848

Published Jul 18, 2026

Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts th…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-12960

Published Jul 3, 2026

An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
15.9
Public PoC observed

CVE-2026-54318

Published Jun 23, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with n…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-68713

Published Jun 15, 2026

An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no per…

CVSS 8.0 · High

CVE-2026-44279

Published May 12, 2026

An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all ve…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3291

Published May 6, 2026

Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-15464

Published Jan 8, 2026

Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-14517

Published Dec 11, 2025

A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity  of the file AndroidManifest.xml. Executing manipulation can lead to improper expo…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2025-10722

Published Sep 19, 2025

A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file AndroidManifest.xml of the component com.dw.android.mukbee. The…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-10721

Published Sep 19, 2025

A vulnerability was determined in Webull Investing & Trading App 11.2.5.63 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml. This manipulation c…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-10718

Published Sep 19, 2025

A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the component com.ooma.office2. The manipulation results in imp…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2025-10717

Published Sep 19, 2025

A vulnerability has been found in intsig CamScanner App 6.91.1.5.250711 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the com…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-10716

Published Sep 19, 2025

A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2025-10715

Published Sep 19, 2025

A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an unknown function of the file AndroidManifest.xml of the com…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-10195

Published Sep 10, 2025

A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.seismic.doccenter. Such manipu…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-5500

Published Sep 9, 2025

A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.xiaoxun.xunoversea.mib…

CVSS 1.9 · Low

CVE-2025-32347

Published Sep 4, 2025

In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of p…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9695

Published Aug 30, 2025

A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of th…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9677

Published Aug 29, 2025

A security flaw has been discovered in Modo Legend of the Phoenix up to 1.0.5. The affected element is an unknown function of the file AndroidManifest.xml of the component com.dui…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9676

Published Aug 29, 2025

A vulnerability was identified in NCSOFT Universe App up to 1.3.0. Impacted is an unknown function of the file AndroidManifest.xml of the component com.ncsoft.universeapp. The man…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9674

Published Aug 29, 2025

A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9673

Published Aug 29, 2025

A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of th…

CVSS 1.9 · Low

CVE-2025-9672

Published Aug 29, 2025

A security vulnerability has been detected in Rejseplanen App up to 8.2.2. Affected is an unknown function of the file AndroidManifest.xml of the component de.hafas.android.rejsep…

CVSS 1.9 · Low

CVE-2025-9671

Published Aug 29, 2025

A weakness has been identified in UAB Paytend App up to 2.1.9 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.passport.cash. Exec…

CVSS 1.9 · Low
Showing 1-25 of 82 CVEsPage 1 of 4