Mobile Apps
23,421 CVEs tracked since 1999. In the last 12 months, 1,736, −12% on the 12 before.
Mobile Apps by subsector, Sep 2026 so far
- Android apps1250% · 4 vendors
- Not yet sub-classified12The tagger has not placed these yet
Month by month
Every monthly snapshot of Mobile Apps. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 269 |
| 2021-10 | 236 |
| 2021-11 | 146 |
| 2021-12 | 309 |
| 2022-01 | 168 |
| 2022-02 | 231 |
| 2022-03 | 246 |
| 2022-04 | 174 |
| 2022-05 | 202 |
| 2022-06 | 173 |
| 2022-07 | 239 |
| 2022-08 | 263 |
| 2022-09 | 333 |
| 2022-10 | 165 |
| 2022-11 | 259 |
| 2022-12 | 368 |
| 2023-01 | 122 |
| 2023-02 | 222 |
| 2023-03 | 0 |
| 2023-04 | 126 |
| 2023-05 | 272 |
| 2023-06 | 297 |
| 2023-07 | 275 |
| 2023-08 | 232 |
| 2023-09 | 319 |
| 2023-10 | 286 |
| 2023-11 | 138 |
| 2023-12 | 306 |
| 2024-01 | 186 |
| 2024-02 | 141 |
| 2024-03 | 202 |
| 2024-04 | 138 |
| 2024-05 | 151 |
| 2024-06 | 177 |
| 2024-07 | 214 |
| 2024-08 | 114 |
| 2024-09 | 209 |
| 2024-10 | 179 |
| 2024-11 | 190 |
| 2024-12 | 202 |
| 2025-01 | 252 |
| 2025-02 | 87 |
| 2025-03 | 237 |
| 2025-04 | 92 |
| 2025-05 | 157 |
| 2025-06 | 70 |
| 2025-07 | 172 |
| 2025-08 | 129 |
| 2025-09 | 314 |
| 2025-10 | 73 |
| 2025-11 | 235 |
| 2025-12 | 244 |
| 2026-01 | 100 |
| 2026-02 | 152 |
| 2026-03 | 319 |
| 2026-04 | 225 |
| 2026-05 | 21 |
| 2026-06 | 24 |
| 2026-07 | 10 |
| 2026-08 | 19 |
| 2026-09 | 24 |
Vendors
Who shipped the most Mobile Apps CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Mobile Apps CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Mobile Apps.
- CVE-2026-100865Heym before 0.0.53 Multiple RCE and Authentication Bypass Vulnerabilities8.8
- CVE-2026-100864heym before 0.0.91 Remote Code Execution via Expression Engine8.8
- CVE-2026-100863Heym before 0.0.91 SSRF via image fetching and IPv6 validation5.0
- CVE-2026-100862heym before 0.0.91 Multiple Secrets Plaintext Storage4.9
- CVE-2026-100861heym before 0.0.105 SSRF via credential-controlled base URLs5.0
- CVE-2026-100860heym before 0.0.105 Authentication Bypass via Redis Node5.5
- CVE-2026-100859Heym before 0.0.106 Credential Exfiltration via URL Override6.5
- CVE-2026-100858heym before 0.0.109 Server-Side Request Forgery via Workflow Nodes6.8
- CVE-2026-97724A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of an object...4.3
- CVE-2026-95627Tauri framework v2 Dialog plugin auto-expands the filesystem scope with attacker-controlled recursion7.7
- CVE-2026-95626Tauri framework v2 CSP nonce protection bypass via data and blob URI schemes allows an XSS to RCE chains8.3
- CVE-2026-95625Tauri framework v2 missing updater signature version number validation can be exploited into forced downgrade5.9
- CVE-2026-19202Token Cache Reuse in mcp-toolbox-sdk-python—
- CVE-2026-95624Tauri framework v2 malicious downgrade via allow_downgrades from frontend code6.8
- CVE-2026-95623Tauri framework v2 SSRF Protection Bypass via HTTP Redirects5.6
The record
- Busiest month
- Dec 2022, 368 CVEs
- Sep 2026 so far
- 24 CVEs from 5 vendors
- Deployment
- On-prem, 95%
- Monthly snapshots
- 282 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment