CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
76 results Clear all
CVE-2025-15464 7.5 HIGH EPSS 0.00
Gmail - Auth Bypass
Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.
CWE-926 Jan 08, 2026
CVE-2025-14517 5.3 MEDIUM EPSS 0.00
Yalantis uCrop 2.2.11 - Info Disclosure
A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity  of the file AndroidManifest.xml. Executing manipulation can lead to improper export of android application components. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Dec 11, 2025
CVE-2025-10722 5.3 MEDIUM 1 Writeup EPSS 0.00
SKTLab Mukbee App 1.01.196 - Info Disclosure
A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file AndroidManifest.xml of the component com.dw.android.mukbee. The manipulation results in improper export of android application components. The attack must be initiated from a local position. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Sep 19, 2025
CVE-2025-10721 5.3 MEDIUM 1 Writeup EPSS 0.00
Webull Investing & Trading App 11.2.5.63 - Info Disclosure
A vulnerability was determined in Webull Investing & Trading App 11.2.5.63 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml. This manipulation causes improper export of android application components. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Sep 19, 2025
CVE-2025-10718 5.3 MEDIUM 1 Writeup EPSS 0.00
Ooma Office Business Phone App <7.2.2 - Info Disclosure
A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the component com.ooma.office2. The manipulation results in improper export of android application components. The attack needs to be approached locally. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Sep 19, 2025
CVE-2025-10717 5.3 MEDIUM 1 Writeup EPSS 0.00
intsig CamScanner App 6.91.1.5.250711 - Info Disclosure
A vulnerability has been found in intsig CamScanner App 6.91.1.5.250711 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.intsig.camscanner. The manipulation leads to improper export of android application components. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Sep 19, 2025
CVE-2025-10716 5.3 MEDIUM 1 Writeup EPSS 0.00
Creality Cloud App <6.1.0 - Info Disclosure
A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cxsw.sdprinter. Executing manipulation can lead to improper export of android application components. It is possible to launch the attack on the local host. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Sep 19, 2025
CVE-2025-10715 5.3 MEDIUM 1 Writeup EPSS 0.00
APEUni PTE Exam Practice App <10.8.0 - Info Disclosure
A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an unknown function of the file AndroidManifest.xml of the component com.ape_edication. The manipulation results in improper export of android application components. The attack requires a local approach. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Sep 19, 2025
CVE-2025-10195 5.3 MEDIUM 1 Writeup EPSS 0.00
Seismic App 2.4.2 - Info Disclosure
A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.seismic.doccenter. Such manipulation leads to improper export of android application components. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Sep 10, 2025
CVE-2025-5500 5.3 MEDIUM 1 Writeup EPSS 0.00
ZhenShi Mibro Fit App 1.6.3.17499 - Info Disclosure
A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.xiaoxun.xunoversea.mibrofit. This manipulation causes improper export of android application components. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Sep 09, 2025
CVE-2025-32347 7.8 HIGH EPSS 0.00
BiometricEnrollIntroduction - Info Disclosure
In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CWE-926 Sep 04, 2025
CVE-2025-9695 5.3 MEDIUM 1 Writeup EPSS 0.00
GalleryVault App <4.5.2 - Info Disclosure
A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.thinkyeah.galleryvault. The manipulation leads to improper export of android application components. The attack can only be performed from a local environment. The exploit is publicly available and might be used.
CWE-926 Aug 30, 2025
CVE-2025-9677 5.3 MEDIUM 1 Writeup EPSS 0.00
Modo Legend of the Phoenix <1.0.5 - Info Disclosure
A security flaw has been discovered in Modo Legend of the Phoenix up to 1.0.5. The affected element is an unknown function of the file AndroidManifest.xml of the component com.duige.hzw.multilingual. The manipulation results in improper export of android application components. The attack needs to be approached locally. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Aug 29, 2025
CVE-2025-9676 5.3 MEDIUM 1 Writeup EPSS 0.00
NCSOFT Universe App <1.3.0 - Info Disclosure
A vulnerability was identified in NCSOFT Universe App up to 1.3.0. Impacted is an unknown function of the file AndroidManifest.xml of the component com.ncsoft.universeapp. The manipulation leads to improper export of android application components. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Aug 29, 2025
CVE-2025-9675 5.3 MEDIUM 1 Writeup EPSS 0.00
Voice Changer App <1.1.0 - Info Disclosure
A vulnerability was determined in Voice Changer App up to 1.1.0. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.tuyangkeji.changevoice. Executing manipulation can lead to improper export of android application components. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized.
CWE-926 Aug 29, 2025
CVE-2025-9674 5.3 MEDIUM 1 Writeup EPSS 0.00
Transbyte Scooper News App <1.2 - Info Disclosure
A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.hatsune.eagleee. This manipulation causes improper export of android application components. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Aug 29, 2025
CVE-2025-9673 5.3 MEDIUM 1 Writeup EPSS 0.00
Kakao Hey Kakao App <2.17.4 - Info Disclosure
A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.kakao.i.connect. The manipulation results in improper export of android application components. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Aug 29, 2025
CVE-2025-9672 5.3 MEDIUM 1 Writeup EPSS 0.00
Rejseplanen App <8.2.2 - Info Disclosure
A security vulnerability has been detected in Rejseplanen App up to 8.2.2. Affected is an unknown function of the file AndroidManifest.xml of the component de.hafas.android.rejseplanen. The manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Aug 29, 2025
CVE-2025-9671 5.3 MEDIUM 1 Writeup EPSS 0.00
UAB Paytend App <2.1.9 - Info Disclosure
A weakness has been identified in UAB Paytend App up to 2.1.9 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.passport.cash. Executing manipulation can lead to improper export of android application components. The attack needs to be launched locally. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
CWE-926 Aug 29, 2025
CVE-2025-9135 5.3 MEDIUM 1 Writeup EPSS 0.00
Verkehrsauskunft Österreich Apps <12.1.1(258) - Info Disclosure
A vulnerability was detected in Verkehrsauskunft Österreich SmartRide, cleVVVer, BusBahnBim and Salzburg Verkehr up to 12.1.1(258) on Android. The impacted element is an unknown function of the file AndroidManifest.xml. The manipulation results in improper export of android application components. The attack must be initiated from a local position. The exploit is now public and may be used. Upgrading to version 12.1.2(259) is sufficient to resolve this issue. Upgrading the affected component is recommended. The vendor was contacted early and fixed the issue by "[r]emoving the task affinity of the app so it can't be copied".
CWE-926 Aug 19, 2025