CWE-939 · 22 kayıt
Improper Authorization in Handler for Custom URL Scheme
Bu sınıftaki CVE’ler
22 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-53407İstismar yok | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allozoom · workplace · CWE-939 | Kritik9,8 | — | %0,4 | 12 Haz 2026 |
35İzleyin | CVE-2023-43582İstismar yok | Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.zoom · meetings · CWE-939 | Yüksek8,8 | — | %0,7 | 14 Kas 2023 |
35İzleyin | CVE-2026-35394İstismar yok | Mobile Next has Arbitrary Android Intent Execution via mobile_open_urlmobilenexthq · mobile mcp · CWE-939 | Yüksek8,8 | — | %0,4 | 6 Nis 2026 |
34İzleyin | CVE-2024-33606İstismar yok | MicroDicom DICOM Viewer Improper Authorization in Handler for Custom URL Schememicrodicom · dicom viewer · CWE-939 | Yüksek8,6 | — | %0,5 | 11 Haz 2024 |
34İzleyin | CVE-2026-6445İstismar yok | A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticatedeverpure · flasharray · CWE-939 | Yüksek8,7 | — | %0,4 | 9 Haz 2026 |
32İzleyin | CVE-2026-53408İstismar yok | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allozoom · meeting software development kit · CWE-939 | Yüksek8,1 | — | %0,4 | 12 Haz 2026 |
26İzleyin | CVE-2020-11000İstismar yok | Improper URL validation in GreenBrowsergreenbrowser project · greenbrowser · CWE-939 | Orta6,5 | — | %1,2 | 8 Nis 2020 |
26İzleyin | CVE-2026-3471İstismar yok | Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop Appmattermost · mattermost desktop · CWE-939 | Orta6,5 | — | %0,3 | 18 May 2026 |
26İzleyin | CVE-2026-1046İstismar yok | Arbitrary application execution via unvalidated server-controlled URLs in Help menumattermost · mattermost desktop · CWE-939 | Orta6,5 | — | %0,2 | 16 Şub 2026 |
25İzleyin | CVE-2026-33335İstismar yok | Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openExternalvikunja · vikunja · CWE-939 | Orta6,4 | — | %0,4 | 24 Mar 2026 |
22İzleyin | CVE-2026-26123İstismar yok | Microsoft Authenticator Information Disclosure Vulnerabilitymicrosoft · authenticator · CWE-939 | Orta5,5 | — | %0,5 | 10 Mar 2026 |
21İzleyin | CVE-2022-20736İstismar yok | Cisco AppDynamics Controller Authorization Bypass Vulnerabilitycisco · appdynamics controller · CWE-939 | Orta5,3 | — | %1,0 | 15 Haz 2022 |
21İzleyin | CVE-2026-21075İstismar yok | Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive informsamsung mobile · my galaxy · CWE-939 | Orta5,3 | — | %0,5 | 10 Ağu 2026 |
21İzleyin | CVE-2025-41408İstismar yok | Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remotely corporation · "yahoo! shopping" app for android · CWE-939 | Orta5,3 | — | %0,3 | 5 Eyl 2025 |
19İzleyin | CVE-2026-21062İstismar yok | Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.samsung · android · CWE-939 | Orta4,8 | — | %0,1 | 10 Ağu 2026 |
18İzleyin | CVE-2026-73335İstismar yok | Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939).digital agency · android app "myna point" · CWE-939 | Orta4,6 | — | %0,1 | 26 Ağu 2026 |
17İzleyin | CVE-2024-45203İstismar yok | Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS veristyle · \@cosme · CWE-939 | Orta4,3 | — | %0,3 | 9 Eyl 2024 |
17İzleyin | CVE-2024-35298İstismar yok | Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 allows an attacker to lzozo, inc. · 'zozotown' app for android · CWE-939 | Orta4,3 | — | %0,3 | 19 Haz 2024 |
17İzleyin | CVE-2025-5020İstismar yok | Links using non-HTTP schemes opened from other apps such as Safari could have allowed spoofing of website addressesmozilla · firefox · CWE-939 | Orta4,3 | — | %0,2 | 21 May 2025 |
14İzleyin | CVE-2024-54014İstismar yok | Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.skylark holdings co., ltd. · 'skylark' app for android · CWE-939 | Düşük3,6 | — | %0,2 | 4 Ara 2024 |
13İzleyin | CVE-2024-54125İstismar yok | Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker tshueisha inc. · "shonen jump+" app for android · CWE-939 | Düşük3,3 | — | %0,2 | 17 Ara 2024 |
12İzleyin | CVE-2025-67739İstismar yok | In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosurejetbrains · teamcity · CWE-939 | Düşük3,1 | — | %0,2 | 11 Ara 2025 |
- CVE-2026-5340739İzleyin
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allo
KritikCVSS 9,8İstismar yokEPSS %0zoom · workplace12 Haz 2026
- CVE-2023-4358235İzleyin
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
YüksekCVSS 8,8İstismar yokEPSS %1zoom · meetings14 Kas 2023
- CVE-2026-3539435İzleyin
Mobile Next has Arbitrary Android Intent Execution via mobile_open_url
YüksekCVSS 8,8İstismar yokEPSS %0mobilenexthq · mobile mcp6 Nis 2026
- CVE-2024-3360634İzleyin
MicroDicom DICOM Viewer Improper Authorization in Handler for Custom URL Scheme
YüksekCVSS 8,6İstismar yokEPSS %0microdicom · dicom viewer11 Haz 2024
- CVE-2026-644534İzleyin
A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated
YüksekCVSS 8,7İstismar yokEPSS %0everpure · flasharray9 Haz 2026
- CVE-2026-5340832İzleyin
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allo
YüksekCVSS 8,1İstismar yokEPSS %0zoom · meeting software development kit12 Haz 2026
- CVE-2020-1100026İzleyin
Improper URL validation in GreenBrowser
OrtaCVSS 6,5İstismar yokEPSS %1greenbrowser project · greenbrowser8 Nis 2020
- CVE-2026-347126İzleyin
Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App
OrtaCVSS 6,5İstismar yokEPSS %0mattermost · mattermost desktop18 May 2026
- CVE-2026-104626İzleyin
Arbitrary application execution via unvalidated server-controlled URLs in Help menu
OrtaCVSS 6,5İstismar yokEPSS %0mattermost · mattermost desktop16 Şub 2026
- CVE-2026-3333525İzleyin
Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openExternal
OrtaCVSS 6,4İstismar yokEPSS %0vikunja · vikunja24 Mar 2026
- CVE-2026-2612322İzleyin
Microsoft Authenticator Information Disclosure Vulnerability
OrtaCVSS 5,5İstismar yokEPSS %1microsoft · authenticator10 Mar 2026
- CVE-2022-2073621İzleyin
Cisco AppDynamics Controller Authorization Bypass Vulnerability
OrtaCVSS 5,3İstismar yokEPSS %1cisco · appdynamics controller15 Haz 2022
- CVE-2026-2107521İzleyin
Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive inform
OrtaCVSS 5,3İstismar yokEPSS %0samsung mobile · my galaxy10 Ağu 2026
- CVE-2025-4140821İzleyin
Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote
OrtaCVSS 5,3İstismar yokEPSS %0ly corporation · "yahoo! shopping" app for android5 Eyl 2025
- CVE-2026-2106219İzleyin
Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.
OrtaCVSS 4,8İstismar yokEPSS %0samsung · android10 Ağu 2026
- CVE-2026-7333518İzleyin
Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939).
OrtaCVSS 4,6İstismar yokEPSS %0digital agency · android app "myna point"26 Ağu 2026
- CVE-2024-4520317İzleyin
Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS ver
OrtaCVSS 4,3İstismar yokEPSS %0istyle · \@cosme9 Eyl 2024
- CVE-2024-3529817İzleyin
Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 allows an attacker to l
OrtaCVSS 4,3İstismar yokEPSS %0zozo, inc. · 'zozotown' app for android19 Haz 2024
- CVE-2025-502017İzleyin
Links using non-HTTP schemes opened from other apps such as Safari could have allowed spoofing of website addresses
OrtaCVSS 4,3İstismar yokEPSS %0mozilla · firefox21 May 2025
- CVE-2024-5401414İzleyin
Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.
DüşükCVSS 3,6İstismar yokEPSS %0skylark holdings co., ltd. · 'skylark' app for android4 Ara 2024
- CVE-2024-5412513İzleyin
Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker t
DüşükCVSS 3,3İstismar yokEPSS %0shueisha inc. · "shonen jump+" app for android17 Ara 2024
- CVE-2025-6773912İzleyin
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
DüşükCVSS 3,1İstismar yokEPSS %0jetbrains · teamcity11 Ara 2025