Skip to main content

CWE archive

CWE-939 CVEs

Programmatic archive

24 CVEs tagged with CWE-9390 Critical, 7 High, 12 Medium, 5 Low, 0 Unrated.

CVE-2026-12190

Published Jun 14, 2026

A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads…

CVSS 4.8 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-12189

Published Jun 14, 2026

A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a manipulation can lead to imprope…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
27.5

CVE-2026-53407

Published Jun 12, 2026

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12065

Published Jun 12, 2026

A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation…

CVSS 0.3 · Low
evidence mentions
7
Buzz score
28.8

CVE-2026-6445

Published Jun 9, 2026

A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-3471

Published May 18, 2026

Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server o…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35394

Published Apr 6, 2026

Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33335

Published Mar 24, 2026

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper passes URLs from `windo…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-26123

Published Mar 10, 2026

Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-1046

Published Feb 16, 2026

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-67739

Published Dec 11, 2025

In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-41408

Published Sep 5, 2025

Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may lead a us…

CVSS 5.3 · Medium

CVE-2025-5020

Published May 21, 2025

Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used inter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54125

Published Dec 17, 2024

Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker to lead a user to access an arbitrary we…

CVSS 3.3 · Low

CVE-2024-54014

Published Dec 5, 2024

Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to le…

CVSS 3.6 · Low

CVE-2024-45203

Published Sep 9, 2024

Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacke…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41918

Published Aug 29, 2024

'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35298

Published Jun 19, 2024

Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 allows an attacker to lead a user to access an arbitrary websi…

CVSS 4.3 · Medium

CVE-2024-33606

Published Jun 11, 2024

An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing medical images on a MicroDicom DICOM Viewer system. User inte…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20736

Published Jun 15, 2022

A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11000

Published Apr 8, 2020

GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many differe…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1