CWE-926
79 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-926page 1 of 2
- CVE-2021-25379MEDIUMCVSS 4.0EG 4.02021-04-09
Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.
- CVE-2021-25388HIGHCVSS 7.1EG 7.12021-06-11
Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.
- CVE-2021-25390MEDIUMCVSS 4.0EG 4.02021-06-11
Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
- CVE-2021-25391MEDIUMCVSS 4.0EG 4.02021-06-11
Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
- CVE-2021-25397MEDIUMCVSS 6.8EG 5.52021-06-11
An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.
- CVE-2021-25400HIGHCVSS 7.8EG 7.82021-06-11
Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
- CVE-2021-25526MEDIUMCVSS 4.0EG 5.52021-12-08
Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.
- CVE-2021-25527LOWCVSS 3.8EG 3.32021-12-08
Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.
- CVE-2021-4438MEDIUMCVSS 5.3EG 5.32024-04-07
A vulnerability, which was classified as critical, has been found in kyivstarteam react-native-sms-user-consent up to 1.1.4 on Android. Affected by this issue is the function registerReceiver of the file android/src/main/java/ua/kyivstar/r…
- CVE-2022-24929MEDIUMCVSS 4.1EG 3.32022-03-10
Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.
- CVE-2023-20962MEDIUMCVSS 5.5EG 5.52023-03-24
In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional executi…
- CVE-2023-21485MEDIUMCVSS 5.3EG 5.32023-05-04
Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
- CVE-2023-21486MEDIUMCVSS 5.3EG 5.32023-05-04
Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
- CVE-2023-30718MEDIUMCVSS 4.0EG 4.02023-09-06
Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity prior to SMR Sep-2023 Release 1 allows local attacker to change a Auto Hotspot setting.
- CVE-2023-41816MEDIUMCVSS 5.0EG 5.02024-05-03
An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.
- CVE-2023-41821MEDIUMCVSS 5.0EG 5.02024-05-03
A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.
- CVE-2023-41822MEDIUMCVSS 4.8EG 4.82024-05-03
An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.
- CVE-2023-41823MEDIUMCVSS 4.4EG 4.42024-05-03
An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities.
- CVE-2023-41827MEDIUMCVSS 5.1EG 5.12024-03-04
An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI.
- CVE-2023-41829MEDIUMCVSS 5.0EG 5.02024-03-04
An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.
- CVE-2023-41960HIGHCVSS 7.1EG 7.12023-10-25
The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive settings of the Android Client application i…
- CVE-2023-44121MEDIUMCVSS 5.0EG 5.02023-09-27
The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device…
- CVE-2023-44129LOWCVSS 3.6EG 3.62023-09-27
The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this …
- CVE-2024-13915MEDIUMCVSS 6.9EG 0.02025-05-30
Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process. The application "com.pri.factorytest" (version name: 1.0, version cod…
- CVE-2024-13916MEDIUMCVSS 6.9EG 0.02025-05-30
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.android.providers.settings.fingerprint.Pri…
- CVE-2024-13917HIGHCVSS 8.3EG 0.02025-05-30
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any …
- CVE-2024-27086LOWCVSS 3.9EG 3.92024-04-16
The MSAL library enabled acquisition of security tokens to call protected APIs. MSAL.NET applications targeting Xamarin Android and .NET Android (e.g., MAUI) using the library from versions 4.48.0 to 4.60.0 are impacted by a low severity v…
- CVE-2024-3479LOWCVSS 2.8EG 2.82024-05-03
An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data.
- CVE-2024-36437MEDIUMCVSS 6.5EG 6.52025-02-03
The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via th…
- CVE-2024-6051MEDIUMCVSS 4.3EG 0.02024-09-30
Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection and to manipulate the view of a vulnerable application.This issue affects Redlink SDK versions through 1.13.
- CVE-2025-10195MEDIUMCVSS 5.3EG 5.32025-09-10
A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.seismic.doccenter. Such manipulation leads to improper export of android application compo…
- CVE-2025-10715MEDIUMCVSS 5.3EG 5.32025-09-19
A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an unknown function of the file AndroidManifest.xml of the component com.ape_edication. The manipulation results in improp…
- CVE-2025-10716MEDIUMCVSS 5.3EG 5.32025-09-19
A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cxsw.sdprinter. Executing manipulation can lead to improper…
- CVE-2025-10717MEDIUMCVSS 5.3EG 5.32025-09-19
A vulnerability has been found in intsig CamScanner App 6.91.1.5.250711 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.intsig.camscanner. The manipulation leads to impr…
- CVE-2025-10718MEDIUMCVSS 5.3EG 5.32025-09-19
A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the component com.ooma.office2. The manipulation results in improper export of android application components. The attack n…
- CVE-2025-10721MEDIUMCVSS 5.3EG 5.32025-09-19
A vulnerability was determined in Webull Investing & Trading App 11.2.5.63 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml. This manipulation causes improper export of android application components. The…
- CVE-2025-10722MEDIUMCVSS 5.3EG 5.32025-09-19
A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file AndroidManifest.xml of the component com.dw.android.mukbee. The manipulation results in improper export of android applicat…
- CVE-2025-14517MEDIUMCVSS 5.3EG 5.32025-12-11
A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity of the file AndroidManifest.xml. Executing manipulation can lead to improper export of android application components. The attack can only b…
- CVE-2025-15464HIGHCVSS 7.5EG 7.52026-01-08
Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.
- CVE-2025-20934MEDIUMCVSS 5.5EG 5.52025-04-08
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.
- CVE-2025-27599MEDIUMCVSS 6.5EG 6.52025-04-18
Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar…
- CVE-2025-32347HIGHCVSS 7.8EG 7.82025-09-04
In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
- CVE-2025-5344HIGHCVSS 8.5EG 0.02025-07-17
Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's…
- CVE-2025-5345MEDIUMCVSS 6.3EG 0.02025-07-17
Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and de…
- CVE-2025-5346MEDIUMCVSS 5.1EG 0.02025-07-17
Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containi…
- CVE-2025-5500MEDIUMCVSS 5.3EG 5.32025-09-09
A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.xiaoxun.xunoversea.mibrofit. This manipulation causes improper export of android a…
- CVE-2025-7889MEDIUMCVSS 5.3EG 5.32025-07-20
A vulnerability was found in CallApp Caller ID App up to 2.0.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component caller.id.phone.number.block. The manipulati…
- CVE-2025-7890MEDIUMCVSS 5.3EG 5.32025-07-20
A vulnerability was found in Dunamu StockPlus App up to 7.62.10 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.dunamu.stockpl…
- CVE-2025-7891MEDIUMCVSS 5.3EG 5.32025-07-20
A vulnerability was found in InstantBits Web Video Cast App up to 5.12.4 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.instantbits.ca…
- CVE-2025-7892MEDIUMCVSS 5.3EG 5.32025-07-20
A vulnerability classified as problematic has been found in IDnow App up to 9.6.0 on Android. This affects an unknown part of the file AndroidManifest.xml of the component de.idnow. The manipulation leads to improper export of android appl…
Map vulnerabilities like CWE-926 to your infrastructure
EchelonGraph correlates every CVE — across CWE-926 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →