CWE-926 · 127 записей
Improper Export of Android Application Components
CVE этого класса
127 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2026-21055Proof of concept | Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands wisamsung mobile · bixby · CWE-926 | Высокая8,5 | — | 0,2 % | 10 июл. 2026 г. |
34Наблюдать | CVE-2026-81301Эксплойта нет | Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file accessekia · file manager · CWE-926 | Высокая8,5 | — | 0,2 % | 14 сент. 2026 г. |
34Наблюдать | CVE-2025-5344Эксплойта нет | Exposed AIDL service allowing for tampering of system secure settings in Bluebird kiosk applicationbluebird · com.bluebird.kiosk.launcher · CWE-926 | Высокая8,5 | — | 0,1 % | 17 июл. 2025 г. |
33Наблюдать | CVE-2024-13917Эксплойта нет | Intent Injection in Kruger&Matz AppLock applicationkruger&matz · com.pri.applock · CWE-926 | Высокая8,3 | — | 0,2 % | 30 мая 2025 г. |
33Наблюдать | CVE-2026-20990Эксплойта нет | Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrarsamsung · android · CWE-926 | Высокая8,4 | — | 0,2 % | 16 мар. 2026 г. |
33Наблюдать | CVE-2026-20983Эксплойта нет | Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrasamsung · android · CWE-926 | Высокая8,4 | — | 0,1 % | 4 февр. 2026 г. |
33Наблюдать | CVE-2026-18994Эксплойта нет | A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in thelenovo · file manager application · CWE-926 | Высокая8,4 | — | 0,1 % | 10 сент. 2026 г. |
32Наблюдать | CVE-2025-68713Эксплойта нет | An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9.CWE-926 | Высокая8,0 | — | 0,3 % | 15 июн. 2026 г. |
31Наблюдать | CVE-2021-25400Эксплойта нет | Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.samsung · internet · CWE-926 | Высокая7,8 | — | 0,2 % | 11 июн. 2021 г. |
31Наблюдать | CVE-2025-32347Эксплойта нет | In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent.google · android · CWE-926 | Высокая7,8 | — | 0,1 % | 4 сент. 2025 г. |
30Наблюдать | CVE-2025-15464Эксплойта нет | KL-001-2026-01: yintibao Fun Print Mobile Unauthorized Access via Context Hijackingyintibao · fun print · CWE-926 | Высокая7,5 | — | 0,5 % | 8 янв. 2026 г. |
29Наблюдать | CVE-2026-45528Эксплойта нет | In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent.google · android · CWE-926 | Высокая7,3 | — | 0,1 % | 8 сент. 2026 г. |
28Наблюдать | CVE-2026-54318Эксплойта нет | Home Assistant: Exported BroadcastReceiver allows local apps to spoof device locationhome-assistant · home assistant companion · CWE-926 | Высокая7,1 | — | 0,2 % | 23 июн. 2026 г. |
28Наблюдать | CVE-2025-21080Эксплойта нет | Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access filsamsung · android · CWE-926 | Высокая7,1 | — | 0,1 % | 1 дек. 2025 г. |
28Наблюдать | CVE-2021-25388Эксплойта нет | Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.google · android · CWE-926 | Высокая7,1 | — | 0,1 % | 11 июн. 2021 г. |
27Наблюдать | CVE-2026-57848Эксплойта нет | Stoat for Android Internal File Disclosure via Exported ShareTargetActivity URI Validationstoatchat · stoat for android · CWE-926 | Средняя6,8 | — | 0,2 % | 18 июл. 2026 г. |
27Наблюдать | CVE-2026-21063Эксплойта нет | Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock fusamsung · android · CWE-926 | Средняя6,8 | — | 0,2 % | 10 авг. 2026 г. |
27Наблюдать | CVE-2024-13915Эксплойта нет | Unrestricted Access to Exported Service in com.pri.factorytestulefone · com.pri.factorytest · CWE-926 | Средняя6,9 | — | 0,2 % | 30 мая 2025 г. |
27Наблюдать | CVE-2024-13916Эксплойта нет | Exposure of Applications' Encryption PINs in Kruger&Matz AppLockkruger&matz · com.pri.applock · CWE-926 | Средняя6,9 | — | 0,2 % | 30 мая 2025 г. |
27Наблюдать | CVE-2025-20897Эксплойта нет | Improper access control in Secure Folder prior to version 1.9.20.50 in Android 14, 1.8.11.0 in Android 13, and 1.7.04.0 in Android 12 allowssamsung mobile · secure folder · CWE-926 | Средняя6,8 | — | 0,2 % | 4 февр. 2025 г. |
27Наблюдать | CVE-2026-21054Эксплойта нет | Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.samsung mobile · inputsharing · CWE-926 | Средняя6,9 | — | 0,2 % | 10 июл. 2026 г. |
27Наблюдать | CVE-2026-3291Эксплойта нет | Samsung Print Service Plugin – Potential Information Disclosurehp · samsung print service plugin · CWE-926 | Средняя6,9 | — | 0,1 % | 6 мая 2026 г. |
27Наблюдать | CVE-2026-21059Эксплойта нет | Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file samsung · android · CWE-926 | Средняя6,9 | — | 0,1 % | 10 авг. 2026 г. |
27Наблюдать | CVE-2026-21032Эксплойта нет | Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacsamsung · assistant · CWE-926 | Средняя6,9 | — | 0,1 % | 5 июн. 2026 г. |
27Наблюдать | CVE-2026-21033Эксплойта нет | Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attsamsung · assistant · CWE-926 | Средняя6,9 | — | 0,1 % | 5 июн. 2026 г. |
- CVE-2026-2105534Наблюдать
Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands wi
ВысокаяCVSS 8,5Proof of conceptEPSS 0 %samsung mobile · bixby10 июл. 2026 г.
- CVE-2026-8130134Наблюдать
Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %ekia · file manager14 сент. 2026 г.
- CVE-2025-534434Наблюдать
Exposed AIDL service allowing for tampering of system secure settings in Bluebird kiosk application
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %bluebird · com.bluebird.kiosk.launcher17 июл. 2025 г.
- CVE-2024-1391733Наблюдать
Intent Injection in Kruger&Matz AppLock application
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %kruger&matz · com.pri.applock30 мая 2025 г.
- CVE-2026-2099033Наблюдать
Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrar
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %samsung · android16 мар. 2026 г.
- CVE-2026-2098333Наблюдать
Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitra
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %samsung · android4 февр. 2026 г.
- CVE-2026-1899433Наблюдать
A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %lenovo · file manager application10 сент. 2026 г.
- CVE-2025-6871332Наблюдать
An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9.
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %15 июн. 2026 г.
- CVE-2021-2540031Наблюдать
Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %samsung · internet11 июн. 2021 г.
- CVE-2025-3234731Наблюдать
In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %google · android4 сент. 2025 г.
- CVE-2025-1546430Наблюдать
KL-001-2026-01: yintibao Fun Print Mobile Unauthorized Access via Context Hijacking
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %yintibao · fun print8 янв. 2026 г.
- CVE-2026-4552829Наблюдать
In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %google · android8 сент. 2026 г.
- CVE-2026-5431828Наблюдать
Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %home-assistant · home assistant companion23 июн. 2026 г.
- CVE-2025-2108028Наблюдать
Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access fil
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %samsung · android1 дек. 2025 г.
- CVE-2021-2538828Наблюдать
Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %google · android11 июн. 2021 г.
- CVE-2026-5784827Наблюдать
Stoat for Android Internal File Disclosure via Exported ShareTargetActivity URI Validation
СредняяCVSS 6,8Эксплойта нетEPSS 0 %stoatchat · stoat for android18 июл. 2026 г.
- CVE-2026-2106327Наблюдать
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock fu
СредняяCVSS 6,8Эксплойта нетEPSS 0 %samsung · android10 авг. 2026 г.
- CVE-2024-1391527Наблюдать
Unrestricted Access to Exported Service in com.pri.factorytest
СредняяCVSS 6,9Эксплойта нетEPSS 0 %ulefone · com.pri.factorytest30 мая 2025 г.
- CVE-2024-1391627Наблюдать
Exposure of Applications' Encryption PINs in Kruger&Matz AppLock
СредняяCVSS 6,9Эксплойта нетEPSS 0 %kruger&matz · com.pri.applock30 мая 2025 г.
- CVE-2025-2089727Наблюдать
Improper access control in Secure Folder prior to version 1.9.20.50 in Android 14, 1.8.11.0 in Android 13, and 1.7.04.0 in Android 12 allows
СредняяCVSS 6,8Эксплойта нетEPSS 0 %samsung mobile · secure folder4 февр. 2025 г.
- CVE-2026-2105427Наблюдать
Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.
СредняяCVSS 6,9Эксплойта нетEPSS 0 %samsung mobile · inputsharing10 июл. 2026 г.
- CVE-2026-329127Наблюдать
Samsung Print Service Plugin – Potential Information Disclosure
СредняяCVSS 6,9Эксплойта нетEPSS 0 %hp · samsung print service plugin6 мая 2026 г.
- CVE-2026-2105927Наблюдать
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file
СредняяCVSS 6,9Эксплойта нетEPSS 0 %samsung · android10 авг. 2026 г.
- CVE-2026-2103227Наблюдать
Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attac
СредняяCVSS 6,9Эксплойта нетEPSS 0 %samsung · assistant5 июн. 2026 г.
- CVE-2026-2103327Наблюдать
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local att
СредняяCVSS 6,9Эксплойта нетEPSS 0 %samsung · assistant5 июн. 2026 г.