VulnSea

CWE-926

CVEs classified under CWE-926, newest first.

12 CVEsRSS

CVE-2026-68928High· 8.6PoC
4d ago

Acode is a powerful text and code editor for Android

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and s…

MidnightAcode-Foundation · AcodeEPSS 0.13%via NVD
CVE-2026-86701Low· 2.5
1w ago

Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components

Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device may exploit the affected component via an Intent, p…

SunlitNTT DOCOMO BUSINESS, Inc. · ManabiPocket for ParentsEPSS 0.10%via NVD
CVE-2026-81301High· 8.5
1w ago

Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the caller-controlled URI path directly to a filesystem path and…

Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the caller-controlled URI path directly to a filesystem path and…

TwilightEkia · File ManagerEPSS 0.11%via NVD
CVE-2026-18994High· 7.1
1w ago

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files wi…

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files wi…

TwilightLenovo · File Manager ApplicationEPSS 0.10%via NVD
CVE-2026-21113Medium· 4.8
1w ago

Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.

Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.

SunlitSamsung Mobile · Visual VoicemailEPSS 0.09%via NVD
CVE-2026-21108Medium· 6.9
1w ago

Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.

Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.

SunlitSamsung Mobile · Bixby TouchEPSS 0.10%via NVD
CVE-2026-45528High· 7.3
2w ago

In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent

In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User…

TwilightGoogle · AndroidEPSS 0.07%via NVD
CVE-2026-20516Medium· 5.5PoC
2w ago

In MiracastService, there is a possible escalation of privilege due to a confused deputy

In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11…

TwilightMediaTek, Inc. · MediaTek chipsetEPSS 0.09%via NVD
CVE-2026-20470None
1mo ago

In Telephony, there is a possible information disclosure due to a missing permission check

In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. …

SunlitEPSS 0.13%via NVD
CVE-2026-57848Medium· 5.5
2mo ago

Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the file to share as a URI supplied through the android.inte…

Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the file to share as a URI supplied through the android.inte…

SunlitEPSS 0.20%via NVD
CVE-2026-12960Medium· 6.0PoC
2mo ago

An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Secur…

An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Secur…

TwilightASUS · Router appEPSS 0.16%via NVD
CVE-2026-44279Medium· 5.5
4mo ago

An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an e…

An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an e…

SunlitEPSS 0.10%via NVD
CWE-926 vulnerabilities (CVEs) · VulnSea