İçeriğe atla
Noroxi

CWE-939 · 22 kayıt

Improper Authorization in Handler for Custom URL Scheme

Bu sınıftaki CVE’ler

22 kayıt

  • CVE-2026-53407
    39İzleyin

    Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allo

    KritikCVSS 9,8İstismar yokEPSS %0

    zoom · workplace12 Haz 2026

  • CVE-2023-43582
    35İzleyin

    Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

    YüksekCVSS 8,8İstismar yokEPSS %1

    zoom · meetings14 Kas 2023

  • CVE-2026-35394
    35İzleyin

    Mobile Next has Arbitrary Android Intent Execution via mobile_open_url

    YüksekCVSS 8,8İstismar yokEPSS %0

    mobilenexthq · mobile mcp6 Nis 2026

  • CVE-2024-33606
    34İzleyin

    MicroDicom DICOM Viewer Improper Authorization in Handler for Custom URL Scheme

    YüksekCVSS 8,6İstismar yokEPSS %0

    microdicom · dicom viewer11 Haz 2024

  • CVE-2026-6445
    34İzleyin

    A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated

    YüksekCVSS 8,7İstismar yokEPSS %0

    everpure · flasharray9 Haz 2026

  • CVE-2026-53408
    32İzleyin

    Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allo

    YüksekCVSS 8,1İstismar yokEPSS %0

    zoom · meeting software development kit12 Haz 2026

  • CVE-2020-11000
    26İzleyin

    Improper URL validation in GreenBrowser

    OrtaCVSS 6,5İstismar yokEPSS %1

    greenbrowser project · greenbrowser8 Nis 2020

  • CVE-2026-3471
    26İzleyin

    Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App

    OrtaCVSS 6,5İstismar yokEPSS %0

    mattermost · mattermost desktop18 May 2026

  • CVE-2026-1046
    26İzleyin

    Arbitrary application execution via unvalidated server-controlled URLs in Help menu

    OrtaCVSS 6,5İstismar yokEPSS %0

    mattermost · mattermost desktop16 Şub 2026

  • CVE-2026-33335
    25İzleyin

    Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openExternal

    OrtaCVSS 6,4İstismar yokEPSS %0

    vikunja · vikunja24 Mar 2026

  • CVE-2026-26123
    22İzleyin

    Microsoft Authenticator Information Disclosure Vulnerability

    OrtaCVSS 5,5İstismar yokEPSS %1

    microsoft · authenticator10 Mar 2026

  • CVE-2022-20736
    21İzleyin

    Cisco AppDynamics Controller Authorization Bypass Vulnerability

    OrtaCVSS 5,3İstismar yokEPSS %1

    cisco · appdynamics controller15 Haz 2022

  • CVE-2026-21075
    21İzleyin

    Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive inform

    OrtaCVSS 5,3İstismar yokEPSS %0

    samsung mobile · my galaxy10 Ağu 2026

  • CVE-2025-41408
    21İzleyin

    Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote

    OrtaCVSS 5,3İstismar yokEPSS %0

    ly corporation · "yahoo! shopping" app for android5 Eyl 2025

  • CVE-2026-21062
    19İzleyin

    Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

    OrtaCVSS 4,8İstismar yokEPSS %0

    samsung · android10 Ağu 2026

  • CVE-2026-73335
    18İzleyin

    Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939).

    OrtaCVSS 4,6İstismar yokEPSS %0

    digital agency · android app "myna point"26 Ağu 2026

  • CVE-2024-45203
    17İzleyin

    Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS ver

    OrtaCVSS 4,3İstismar yokEPSS %0

    istyle · \@cosme9 Eyl 2024

  • CVE-2024-35298
    17İzleyin

    Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 allows an attacker to l

    OrtaCVSS 4,3İstismar yokEPSS %0

    zozo, inc. · 'zozotown' app for android19 Haz 2024

  • CVE-2025-5020
    17İzleyin

    Links using non-HTTP schemes opened from other apps such as Safari could have allowed spoofing of website addresses

    OrtaCVSS 4,3İstismar yokEPSS %0

    mozilla · firefox21 May 2025

  • CVE-2024-54014
    14İzleyin

    Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.

    DüşükCVSS 3,6İstismar yokEPSS %0

    skylark holdings co., ltd. · 'skylark' app for android4 Ara 2024

  • CVE-2024-54125
    13İzleyin

    Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker t

    DüşükCVSS 3,3İstismar yokEPSS %0

    shueisha inc. · "shonen jump+" app for android17 Ara 2024

  • CVE-2025-67739
    12İzleyin

    In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure

    DüşükCVSS 3,1İstismar yokEPSS %0

    jetbrains · teamcity11 Ara 2025

Tüm zafiyet sınıfları