CVE-2026-24490
- EPSS 0.01%
- Veröffentlicht 27.01.2026 00:40:36
- Zuletzt bearbeitet 17.02.2026 20:36:16
MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an attacker to execute arbitrary JavaScript in the context of a victim's b...
CVE-2025-58162
- EPSS 0.15%
- Veröffentlicht 02.09.2025 00:46:06
- Zuletzt bearbeitet 03.09.2025 15:48:23
MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF process. This issue has been patch...
CVE-2025-58161
- EPSS 0.12%
- Veröffentlicht 02.09.2025 00:45:49
- Zuletzt bearbeitet 03.09.2025 15:48:43
MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.commonprefix, which allows an authenticated user to download files outside the DWD_DIR download directory f...
CVE-2025-46730
- EPSS 0.31%
- Veröffentlicht 05.05.2025 19:32:24
- Zuletzt bearbeitet 03.09.2025 18:18:17
MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to inte...
CVE-2025-46335
- EPSS 0.15%
- Veröffentlicht 05.05.2025 18:23:59
- Zuletzt bearbeitet 28.05.2025 20:06:23
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has been identified in MobSF versions up to and including 4.3.2. The vulne...
CVE-2025-31116
- EPSS 0.31%
- Veröffentlicht 31.03.2025 17:15:42
- Zuletzt bearbeitet 12.06.2025 19:43:33
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerab...
CVE-2025-24803
- EPSS 0.21%
- Veröffentlicht 05.02.2025 19:15:46
- Zuletzt bearbeitet 07.07.2025 13:41:11
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanume...
CVE-2025-24805
- EPSS 0.09%
- Veröffentlicht 05.02.2025 19:15:46
- Zuletzt bearbeitet 23.05.2025 17:01:45
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for ma...
CVE-2025-24804
- EPSS 0.16%
- Veröffentlicht 05.02.2025 19:15:46
- Zuletzt bearbeitet 23.05.2025 17:18:30
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanume...
CVE-2024-54000
- EPSS 0.17%
- Veröffentlicht 03.12.2024 16:15:24
- Zuletzt bearbeitet 27.06.2025 15:17:02
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the _check_url method is specified as ...