Threats Tagged 'cwe-939'
View all threats tagged with 'cwe-939'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-939'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-21075 is a medium severity vulnerability in Samsung Mobile's My Galaxy application prior to version 6.3. It involves improper authorization in the handler for a custom URL scheme, which allows remote attackers to access sensitive information. No specific affected versions or patches have been confirmed. The vulnerability does not require privileges or user interaction for exploitation but has low impact on confidentiality and no impact on integrity or availability. Join the discussion | CVE Database V5 | 08/10/2026, 07:42:42 UTC Added: 08/10/2026, 08:26:50 UTC |
0 CVE-2026-21062 is an authorization bypass vulnerability in the SemClipboardService component of Samsung Mobile Devices prior to the SMR August 2026 Release 1. This flaw allows local attackers with limited privileges to access clipboard data without proper authorization. The vulnerability has a medium severity rating with a CVSS score of 4.8. No official patch or remediation guidance has been provided yet. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 08/10/2026, 07:40:17 UTC Added: 08/10/2026, 07:41:47 UTC |
0 Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL fragment from a homeassistant://invite deep link into the onboarding flow without ever displaying the destination hostname. Because no screen in the invitation or onboarding flow shows the parsed server URL before onboarding commits to it, a victim has no way to distinguish a legitimate invite from a malicious one. An attacker can craft an invite so that a single tap on the legitimate-looking "Connect to my Home Assistant server" button opens their /auth/authorize endpoint in the URL-less onboarding WebView, presenting a look-alike login page that captures the victim's credentials. Since invitations are intended to onboard brand-new users, targets are especially unlikely to notice the substitution. This issue is fixed in version 2026.6.1. Join the discussion | CVE Database V5 | 08/07/2026, 20:19:14 UTC Added: 08/07/2026, 20:27:00 UTC |
0 Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. Join the discussion | CVE Database V5 | 06/12/2026, 17:57:01 UTC Added: 06/12/2026, 18:55:17 UTC |
0 CVE-2026-53407 is a high-severity vulnerability in Zoom Communications' Zoom Workplace application affecting versions before 7.0.4 on Android and before 7.0.3 on iOS. It involves improper authorization in the handler for a custom URL scheme, which may allow an unauthenticated user to escalate privileges via network access. The vulnerability has a CVSS score of 8.1, indicating a significant risk to confidentiality and integrity without impacting availability. No official patch or vendor advisory is provided in the data. No known exploits in the wild have been reported. Join the discussion | GCVE Database | 06/12/2026, 17:56:26 UTC Added: 06/10/2026, 11:47:51 UTC |
0 A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges. Join the discussion | CVE Database V5 | 06/09/2026, 18:40:03 UTC Added: 06/09/2026, 19:41:19 UTC |
0 CVE-2026-35394 is a high-severity vulnerability in the mobile-next mobile-mcp product prior to version 0.0.50. The mobile_open_url tool improperly authorizes user-supplied URLs by passing them directly to Android's intent system without validating the URL scheme. This allows attackers to execute arbitrary Android intents, potentially triggering USSD codes, phone calls, SMS messages, or accessing content providers. The vulnerability is fixed in version 0.0.50. Join the discussion | CVE Database V5 | 04/06/2026, 20:52:25 UTC Added: 04/06/2026, 21:00:30 UTC |
0 CVE-2026-33335 is a medium-severity vulnerability in the Vikunja Desktop Electron wrapper versions from 0.21.0 up to but not including 2.2.0. The issue arises because URLs passed to window.open() are forwarded directly to shell.openExternal() without validation or protocol allowlisting. This allows an attacker who can embed links with target="_blank" or trigger window.open in user-generated content to cause the victim's OS to open arbitrary URI schemes. Join the discussion | CVE Database V5 | 03/24/2026, 15:07:41 UTC Added: 03/24/2026, 15:45:54 UTC |
0 Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 03/10/2026, 19:01:31 UTC Added: 03/10/2026, 19:30:01 UTC |
0 In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure Join the discussion | CVE Database V5 | 12/11/2025, 15:19:05 UTC Added: 12/11/2025, 15:38:57 UTC |
Showing 1 to 10 of 10 results