The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.
Volume of CVEs assigned to CWE-939 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-53407CRITICAL Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an | Jun 12, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-6445HIGH A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges. | Jun 9, 2026 | 8.7 | 33 | NO | NO |
CVE-2026-53408HIGH Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an | Jun 12, 2026 | 8.1 | 32 | NO | NO |
CVE-2021-31384CRITICAL Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SR | Oct 19, 2021 | 10.0 | 31 | NO | NO |
CVE-2026-35394HIGH Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent s | Apr 6, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-12190MEDIUM A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads | Jun 14, 2026 | 5.3 | 25 | NO | NO |
CVE-2026-12189MEDIUM A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a manipulation can lead to improper | Jun 14, 2026 | 5.3 | 25 | NO | NO |
CVE-2026-3471MEDIUM Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server ow | May 18, 2026 | 6.5 | 25 | NO | NO |
CVE-2026-33335HIGH Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper passes URLs from `window | Mar 24, 2026 | 8.0 | 25 | NO | NO |
CVE-2024-33606HIGH An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing medical images on a MicroDicom DICOM Viewer system. User inter | Jun 11, 2024 | 8.8 | 25 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.