CVE Tools

Mobile Apps

23,421 CVEs tracked since 1999. In the last 12 months, 1,736, −12% on the 12 before.

Mobile Apps by subsector, Sep 2026 so far

Sep 2026 so far: 24 CVEs across 2 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • Android apps1250% · 4 vendors
  • Not yet sub-classified12The tagger has not placed these yet

Month by month

Every monthly snapshot of Mobile Apps. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Mobile Apps CVEs per month
MonthCVEs
2021-09269
2021-10236
2021-11146
2021-12309
2022-01168
2022-02231
2022-03246
2022-04174
2022-05202
2022-06173
2022-07239
2022-08263
2022-09333
2022-10165
2022-11259
2022-12368
2023-01122
2023-02222
2023-030
2023-04126
2023-05272
2023-06297
2023-07275
2023-08232
2023-09319
2023-10286
2023-11138
2023-12306
2024-01186
2024-02141
2024-03202
2024-04138
2024-05151
2024-06177
2024-07214
2024-08114
2024-09209
2024-10179
2024-11190
2024-12202
2025-01252
2025-0287
2025-03237
2025-0492
2025-05157
2025-0670
2025-07172
2025-08129
2025-09314
2025-1073
2025-11235
2025-12244
2026-01100
2026-02152
2026-03319
2026-04225
2026-0521
2026-0624
2026-0710
2026-0819
2026-0924

Vendors

Who shipped the most Mobile Apps CVEs in Sep 2026 so far, with their rank across all vendors.

  1. Google516#4
  2. Apple246#6
  3. Samsung38#26
  4. Huawei11#108

Weaknesses

The weakness classes behind Mobile Apps CVEs in Sep 2026 so far.

  1. CWE-269 Improper Privilege Mgmt3
  2. CWE-125 Out-of-bounds Read2
  3. CWE-284 Improper Access Control2
  4. CWE-79 XSS1
  5. CWE-122 Heap Buffer Overflow1
  6. CWE-416 Use After Free1

Latest CVEs

The 15 most recently published vulnerabilities in Mobile Apps.

  1. CVE-2026-100865Heym before 0.0.53 Multiple RCE and Authentication Bypass Vulnerabilities8.8
  2. CVE-2026-100864heym before 0.0.91 Remote Code Execution via Expression Engine8.8
  3. CVE-2026-100863Heym before 0.0.91 SSRF via image fetching and IPv6 validation5.0
  4. CVE-2026-100862heym before 0.0.91 Multiple Secrets Plaintext Storage4.9
  5. CVE-2026-100861heym before 0.0.105 SSRF via credential-controlled base URLs5.0
  6. CVE-2026-100860heym before 0.0.105 Authentication Bypass via Redis Node5.5
  7. CVE-2026-100859Heym before 0.0.106 Credential Exfiltration via URL Override6.5
  8. CVE-2026-100858heym before 0.0.109 Server-Side Request Forgery via Workflow Nodes6.8
  9. CVE-2026-97724A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of an object...4.3
  10. CVE-2026-95627Tauri framework v2 Dialog plugin auto-expands the filesystem scope with attacker-controlled recursion7.7
  11. CVE-2026-95626Tauri framework v2 CSP nonce protection bypass via data and blob URI schemes allows an XSS to RCE chains8.3
  12. CVE-2026-95625Tauri framework v2 missing updater signature version number validation can be exploited into forced downgrade5.9
  13. CVE-2026-19202Token Cache Reuse in mcp-toolbox-sdk-python—
  14. CVE-2026-95624Tauri framework v2 malicious downgrade via allow_downgrades from frontend code6.8
  15. CVE-2026-95623Tauri framework v2 SSRF Protection Bypass via HTTP Redirects5.6

The record

Busiest month
Dec 2022, 368 CVEs
Sep 2026 so far
24 CVEs from 5 vendors
Deployment
On-prem, 95%
Monthly snapshots
282 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store