Solution sectors / mobile-apps
Mobile Apps
Mobile applications and the cross-platform frameworks behind them handle personal data and run on devices people carry everywhere. This hub tracks CVEs across the mobile app ecosystem.
Cumulative CVEs
23,380
across 281 monthly snapshots
Latest month
5 · proj
-50.0% MoM · -96.1% YoY
Peak month
368
Dec 22
KEV this month
0
2 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem100%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Mobile Apps.
- CVE-2026-67180Google Turbinia arbitrary command execution8.4
- CVE-2026-18907PathTravelsal Vulnerability in com.talpa.hibrowser7.5
- CVE-2026-14541Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider7.5
- CVE-2026-14540Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox6.1
- CVE-2026-14539Denial of Service via Unrestricted Payload Buffering in MCP Toolbox7.5
- CVE-2026-14538BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox7.7
- CVE-2026-14537Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints9.8
- CVE-2026-43820NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed...7.7
- CVE-2026-15017MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers8.8
- CVE-2026-9222Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication8.1
- CVE-2026-9221Setracker2 Children's Smartwatch Ecosystem Use of a Broken or Risky Cryptographic Algorithm7.5
- CVE-2026-9220Setracker2 Children's Smartwatch Ecosystem Use of hard-coded cryptographic key7.5
- CVE-2026-9219Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers6.5
- CVE-2026-12537Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows7.8
- CVE-2026-55740SQL Injection in Nur-Alam39 bus-ticket bus_info.php via busid parameter9.8
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| 43 | 8 | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| android-app | 2 | · | · | 2 | — | @a2ui/web_core (1) · hi browser (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification