Vulnerabilidades en MobSF

20 resultados
Análisis Vexday

O MobSF apresenta 16 vulnerabilidades documentadas na base, todas de severidade baixa a média, com destaque para problemas de injeção (CWE-79). Nenhuma vulnerabilidade está sob exploração ativa conhecida ou foi publicada recentemente, indicando risco controlado e sem urgência imediata de ação.

CVE-2024-41955MEDIUMMobile Security Framework (MobSF) has an Open Redirect in Login RedirectEPSS 1.0%CVE-2024-43399HIGHMobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library FilesEPSS 1.0%CVE-2025-58161LOWMobSF Path Traversal in GET /download/<filename> using absolute filenamesEPSS 0.8%CVE-2024-29190HIGHMobSF SSRF Vulnerability on assetlinks_check(act_name, well_knowns)EPSS 0.7%CVE-2025-58162MEDIUMMobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a ExtractionEPSS 0.6%CVE-2024-53999HIGHMobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" FunctionalityEPSS 0.5%CVE-2024-31215MEDIUMMobile Security Framework (MobSF) vulnerable to Server-Side Request Forgery (SSRF) in firebase database checkEPSS 0.5%CVE-2026-68924MEDIUMMobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK ExtractionEPSS 0.5%CVE-2025-46730MEDIUMMobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death AttackEPSS 0.5%CVE-2025-31116MEDIUMMobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS RebindingEPSS 0.5%CVE-2025-24804MEDIUMPartial Denial of Service (DoS) in MobSFEPSS 0.5%CVE-2026-68922MEDIUMMobSF: Arbitrary File Read via Path Traversal in ZIP UploadsEPSS 0.4%CVE-2024-54000HIGHMobile Security Framework (MobSF) bypass of SSRF fixEPSS 0.4%CVE-2025-24803HIGHStored Cross-Site Scripting (XSS) in MobSFEPSS 0.4%CVE-2025-24805HIGHLocal Privilege Escalation in MobSFEPSS 0.4%CVE-2026-68927LOWMobSF: SSRF port restriction bypass in assetlinks_checkEPSS 0.3%CVE-2026-24490HIGHMobSF has Stored XSS via Manifest Analysis - Dialer Code Host FieldEPSS 0.3%CVE-2025-46335HIGHMobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon UploadEPSS 0.3%CVE-2026-33545MEDIUMMobSF has SQL Injection in its SQLite Database Viewer UtilsEPSS 0.3%CVE-2026-68923MEDIUMMobSF: CSRF checks not enforced after Django migrationEPSS 0.2%