Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-68924Medium· 4.9MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs that an archive member exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE is being skipped but do…
CVE-2026-68927Low· 3.0MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before ap…
CVE-2026-68923Medium· 6.5MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware only in the deprecated MIDDLEWARE_CLASSES setting and omits it from the active MIDDLEWARE …
CVE-2026-68922Medium· 5.5MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py uses the Android manifest android:icon value to construct paths under the scan resource d…
CVE-2026-33545Medium· 5.3MobSF has SQL Injection in its SQLite Database Viewer Utils
CVE-2026-24490High· 8.1MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
CVE-2025-58161LowMobSF Path Traversal in GET /download/<filename> using absolute filenames
CVE-2025-58162Medium· 6.5MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
CVE-2025-46335MediumMobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
CVE-2025-46730Medium· 6.8Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
CVE-2025-24804Medium· 6.5MobSF Partial Denial of Service (DoS)
CVE-2025-24803High· 8.1MobSF Stored Cross-Site Scripting (XSS)
CVE-2025-24805Medium· 6.5MobSF Local Privilege Escalation
CVE-2024-53999Medium· 6.1Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality
CVE-2024-43399High· 8.0Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
CVE-2024-41955Medium· 5.2PoCMobSF vulnerable to Open Redirect in Login Redirect
CVE-2024-31215Medium· 6.3Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check
CVE-2022-41547High· 7.5MobSF allows attackers to read arbitrary files via a crafted HTTP request
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.