Vulnerability index

Browse CVEs

38 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

File Manager CRITICAL 9.8
CVE-2023-26321

A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltere…

Mitigation only
Fix from $2,300 2024-08-28
Redmi Ax6s Firmware MEDIUM 5.2
CVE-2024-37664

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traf…

No fix yet
Fix from $1,600 2024-06-17
Xiaomi 13 Pro Firmware CRITICAL 9.6
CVE-2024-4405

Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…

Mitigation only
Fix from $2,300 2024-05-02
Xiaomi 13 Pro Firmware CRITICAL 9.6
CVE-2024-4406

Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…

Mitigation only
Fix from $2,300 2024-05-02
Xiaomi CRITICAL 9.8
CVE-2020-14129

A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attac…

No fix yet
Fix from $2,300 2022-10-11
Xiaomi CRITICAL 9.8
CVE-2020-14131

The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional sec…

No fix yet
Fix from $2,300 2022-10-11
Xiaomi Lamp 1 Firmware HIGH 8.8
CVE-2022-31277

Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and …

No fix yet
Fix from $1,950 2022-06-16
Miui HIGH 7.5
CVE-2020-14123

There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, …

Mitigation only
Fix from $1,950 2022-04-22
Miui HIGH 8.8
CVE-2020-14120

Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party applic…

No fix yet
Fix from $1,950 2022-04-21
Mi App Store MEDIUM 5.5
CVE-2020-14121

A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, an…

Mitigation only
Fix from $1,600 2022-04-21
Miui MEDIUM 5.5
CVE-2020-14122

Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter v…

Mitigation only
Fix from $1,600 2022-04-21
Mi True Wireless Earbuds Basic 2 Firmware MEDIUM 6.5
CVE-2021-31610

The Bluetooth Classic implementation on AB32VG1 devices does not properly handle the reception of continuous unsolicited LMP responses, allowing atta…

Mitigation only
Fix from $1,600 2021-09-07
Xiaomi Xiaoai Speaker Pro Lx06 Firmware MEDIUM 6.8
CVE-2020-10262

An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.58.10. Attackers can activate the failsafe mode during the boot process, and use the mi_c…

No fix yet
Fix from $1,600 2020-04-08
Xiaomi Xiaoai Speaker Pro Lx06 Firmware MEDIUM 6.8
CVE-2020-10263

An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.52.4. Attackers can get root shell by accessing the UART interface and then they can (i) …

No fix yet
Fix from $1,600 2020-04-08
Miui Firmware HIGH 7.3
CVE-2020-9531

An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. In the Web resources of GetApps(com.xiaomi.mipicks), the parameters passed in are r…

Mitigation only
Fix from $1,950 2020-03-06
Miui Firmware MEDIUM 6.5
CVE-2020-9530

An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. The export component of GetApps(com.xiaomi.mipicks) mishandles the functionality of…

Mitigation only
Fix from $1,600 2020-03-06
Mdz 25 Dt Firmware MEDIUM 6.8
CVE-2020-8994

An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing the UART interface and then th…

No fix yet
Fix from $1,600 2020-03-05
Dgnwg03lm Firmware CRITICAL 9.8
CVE-2019-15913

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communic…

No fix yet
Fix from $2,300 2019-12-20
Dgnwg03lm Firmware HIGH 7.5
CVE-2019-15914

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin pro…

No fix yet
Fix from $1,950 2019-12-20
Dgnwg03lm Firmware HIGH 7.5
CVE-2019-15915

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to…

No fix yet
Fix from $1,950 2019-12-20
A2 Lite Firmware MEDIUM 5.5
CVE-2019-15468

The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/daisy/daisy_sprout:9/PKQ1.180917.001/V10.0.3.0.PDLMIXM:user/release-keys cont…

Mitigation only
Fix from $1,600 2019-11-14
Pad 4 Firmware MEDIUM 5.5
CVE-2019-15469

The Xiaomi Mi Pad 4 Android device with a build fingerprint of Xiaomi/clover/clover:8.1.0/OPM1.171019.019/V9.6.26.0.ODJCNFD:user/release-keys contain…

Mitigation only
Fix from $1,600 2019-11-14
Redmi Note 6 Pro Firmware MEDIUM 5.5
CVE-2019-15470

The Xiaomi Redmi Note 6 Pro Android device with a build fingerprint of xiaomi/tulip/tulip:8.1.0/OPM1.171019.011/V10.2.2.0.OEKMIXM:user/release-keys c…

Mitigation only
Fix from $1,600 2019-11-14
Mix 2s Firmware MEDIUM 5.5
CVE-2019-15471

The Xiaomi Mi Mix 2S Android device with a build fingerprint of Xiaomi/polaris/polaris:8.0.0/OPR1.170623.032/V9.5.19.0.ODGMIFA:user/release-keys cont…

Mitigation only
Fix from $1,600 2019-11-14
A2 Lite Firmware MEDIUM 5.5
CVE-2019-15472

The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/daisy/daisy_sprout:9/PKQ1.180917.001/V10.0.3.0.PDLMIXM:user/release-keys cont…

Mitigation only
Fix from $1,600 2019-11-14
A2 Lite Firmware MEDIUM 5.5
CVE-2019-15473

The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/jasmine/jasmine_sprout:9/PKQ1.180904.001/V10.0.2.0.PDIMIFJ:user/release-keys …

Mitigation only
Fix from $1,600 2019-11-14
Cepheus Firmware MEDIUM 5.5
CVE-2019-15474

The Xiaomi Cepheus Android device with a build fingerprint of Xiaomi/cepheus/cepheus:9/PKQ1.181121.001/V10.2.6.0.PFAMIXM:user/release-keys contains a…

Mitigation only
Fix from $1,600 2019-11-14
A3 Firmware MEDIUM 5.5
CVE-2019-15475

The Xiaomi Mi A3 Android device with a build fingerprint of xiaomi/onc_eea/onc:9/PKQ1.181021.001/V10.2.8.0.PFLEUXM:user/release-keys contains a pre-i…

Mitigation only
Fix from $1,600 2019-11-14
Xiaomi Millet Firmware HIGH 7.4
CVE-2019-15843

A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition involving a man-in-the-middle a…

Mitigation only
Fix from $1,950 2019-09-18
Stock Browser MEDIUM 5.3
CVE-2018-20523EPSS 10%

Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a …

No fix yet
Fix from $1,600 2019-06-07