CWE-926 类弱点 74 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-926指Android应用组件导出不当,属于权限配置缺陷。攻击者利用未受限制的组件,通过其他应用发起恶意请求或窃取敏感数据,导致隐私泄露或服务滥用。开发者应避免使用隐式意图,显式指定组件权限,严格校验调用来源,并最小化组件导出范围,确保仅授权可信应用访问,从而有效阻断未授权访问路径。
<activity android:name="com.example.vulnerableApp.mainScreen"> ... <intent-filter> <action android:name="com.example.vulnerableApp.OPEN_UI" /> <category android:name="android.intent.category.DEFAULT" /> </intent-filter> ... </activity> <service android:name="com.example.vulnerableApp.backgroundService"> ... <intent-filter> <action android:name="com.example.vulnerableApp.START_BACKGROUND" /> </intent-filter> ... </service><provider> android:name="com.example.vulnerableApp.searchDB" android:authorities="com.example.vulnerableApp.searchDB"> </provider>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-44279 | Fortinet FortiTokenAndroid 安全漏洞 — FortiTokenAndroid | 5.0 | Medium | 2026-05-12 |
| CVE-2026-3291 | HP Samsung Print Service Plugin 安全漏洞 — Samsung Print Service Plugin | 4.6AI | MediumAI | 2026-05-06 |
| CVE-2025-15464 | yintibao Fun Print Mobile 安全漏洞 — Fun Print Mobile | 6.5 | - | 2026-01-08 |
| CVE-2025-14517 | uCrop 安全漏洞 — uCrop | 5.3 | Medium | 2025-12-11 |
| CVE-2025-10722 | SKTLab Mukbee App 安全漏洞 — Mukbee App | 5.3 | Medium | 2025-09-19 |
| CVE-2025-10721 | Webull Investing & Trading App 安全漏洞 — Investing & Trading App | 5.3 | Medium | 2025-09-19 |
| CVE-2025-10718 | Ooma Office Business Phone App 安全漏洞 — Office Business Phone App | 5.3 | Medium | 2025-09-19 |
| CVE-2025-10717 | INTSIG CamScanner App 安全漏洞 — CamScanner App | 5.3 | Medium | 2025-09-19 |
| CVE-2025-10716 | Creality Cloud App 安全漏洞 — Cloud App | 5.3 | Medium | 2025-09-19 |
| CVE-2025-10715 | APEUni PTE Exam Practice App 安全漏洞 — PTE Exam Practice App | 5.3 | Medium | 2025-09-19 |
| CVE-2025-10195 | Seismic App 安全漏洞 — Seismic App | 5.3 | Medium | 2025-09-10 |
| CVE-2025-5500 | ZhenShi Mibro Fit App 安全漏洞 — Mibro Fit App | 5.3 | Medium | 2025-09-09 |
| CVE-2025-9695 | GalleryVault Gallery Vault App 安全漏洞 — Gallery Vault App | 5.3 | Medium | 2025-08-30 |
| CVE-2025-9677 | Modo Legend of the Phoenix 安全漏洞 — Legend of the Phoenix | 5.3 | Medium | 2025-08-29 |
| CVE-2025-9676 | NCSOFT Universe App 安全漏洞 — Universe App | 5.3 | Medium | 2025-08-29 |
| CVE-2025-9675 | Baviux Voice Changer App 安全漏洞 — Voice Changer App | 5.3 | Medium | 2025-08-29 |
| CVE-2025-9674 | Transbyte Scooper News App 安全漏洞 — Scooper News App | 5.3 | Medium | 2025-08-29 |
| CVE-2025-9673 | Kakao Hey Kakao App 安全漏洞 — 헤이카카오 Hey Kakao App | 5.3 | Medium | 2025-08-29 |
| CVE-2025-9672 | Rejseplanen App 安全漏洞 — Rejseplanen App | 5.3 | Medium | 2025-08-29 |
| CVE-2025-9671 | UAB Paytend App 安全漏洞 — Paytend App | 5.3 | Medium | 2025-08-29 |
| CVE-2025-9135 | Verkehrsauskunft Österreich多款产品 安全漏洞 — SmartRide | 5.3 | Medium | 2025-08-19 |
| CVE-2025-9134 | AfterShip Package Tracker App 安全漏洞 — Package Tracker App | 5.3 | Medium | 2025-08-19 |
| CVE-2025-9102 | 1&1 Mail & Media mail.com App 安全漏洞 — mail.com App | 5.3 | Medium | 2025-08-18 |
| CVE-2025-9098 | Elseplus File Recovery App 安全漏洞 — File Recovery App | 5.3 | Medium | 2025-08-18 |
| CVE-2025-9097 | Euro Information CIC banque et compte en ligne App 安全漏洞 — CIC banque et compte en ligne App | 5.3 | Medium | 2025-08-18 |
| CVE-2025-9093 | BuzzFeed App 安全漏洞 — BuzzFeed App | 5.3 | Medium | 2025-08-17 |
| CVE-2025-8745 | Weee RICEPO App 安全漏洞 — RICEPO App | 5.3 | Medium | 2025-08-09 |
| CVE-2025-8707 | Huuge Box App 安全漏洞 — Box App | 5.3 | Medium | 2025-08-08 |
| CVE-2025-8524 | DotWallet App 安全漏洞 — DotWallet App | 5.3 | Medium | 2025-08-04 |
| CVE-2025-8523 | RiderLike Fruit Crush-Brain App 安全漏洞 — Fruit Crush-Brain App | 5.3 | Medium | 2025-08-04 |
CWE-926 是常见的弱点类别,本平台收录该类弱点关联的 74 条 CVE 漏洞。