Vulnerability index

Browse CVEs

91 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-45348 Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, … Ax9000 Firmware 1.0.174+ Fix from $1,9502024-09-23 CRITICAL 9.8 CVE-2023-26321 A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltere… File Manager Mitigation only Fix from $2,3002024-08-28 CRITICAL 9.8 CVE-2023-26322 A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed… Getapps 32.0.0.1+ Fix from $2,3002024-08-28 CRITICAL 9.8 CVE-2023-26323 A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by a… App Market 4.58.2+ Fix from $2,3002024-08-28 CRITICAL 9.8 CVE-2023-26324 A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed… Getapps 30.6.0.2+ Fix from $2,3002024-08-28 HIGH 8.8 CVE-2023-26315EPSS 19% The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allo… Ax9000 Firmware 1.0.174+ Fix from $1,9502024-08-26 MEDIUM 5.2 CVE-2024-37664 Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traf… Redmi Ax6s Firmware No fix yet Fix from $1,6002024-06-17 CRITICAL 9.6 CVE-2024-4405 Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute… Xiaomi 13 Pro Firmware Mitigation only Fix from $2,3002024-05-02 CRITICAL 9.6 CVE-2024-4406 Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex… Xiaomi 13 Pro Firmware Mitigation only Fix from $2,3002024-05-02 HIGH 8.1 CVE-2023-26320 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. Xiaomi Router Ax3200 Firmware 2023.2+ Fix from $1,9502023-10-11 HIGH 7.2 CVE-2023-26319 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. Xiaomi Router Ax3200 Firmware 2023.2+ Fix from $1,9502023-10-11 HIGH 7.2 CVE-2023-26318 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers. Xiaomi Router Ax3200 Firmware 2023.2+ Fix from $1,9502023-10-11 CRITICAL 9.8 CVE-2023-26317 Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external… Xiaomi Router Firmware 2023.2+ Fix from $2,3002023-08-02 MEDIUM 6.1 CVE-2023-26316 A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allo… Xiaomi Cloud after 1.12.0.0.25 Fix from $1,6002023-08-02 HIGH 7.5 CVE-2020-14140 When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is ca… Xiaomi Router Firmware 2023.2+ Fix from $1,9502023-03-29 CRITICAL 9.8 CVE-2020-14129 A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attac… Xiaomi No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2020-14131 The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional sec… Xiaomi No fix yet Fix from $2,3002022-10-11 HIGH 7.5 CVE-2020-14114 information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, … Smarthome after 6.4.701 Fix from $1,9502022-07-22 HIGH 7.5 CVE-2020-14126 Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which ca… Sound after 2.2.40 Fix from $1,9502022-07-22 HIGH 7.5 CVE-2020-14127 A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow and can be exploited by attack… Miui 2022.07.01+ Fix from $1,9502022-07-14 HIGH 8.8 CVE-2022-31277 Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and … Xiaomi Lamp 1 Firmware No fix yet Fix from $1,9502022-06-16 HIGH 7.5 CVE-2020-14125EPSS 7% A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited… Miui 2022.01.26+ Fix from $1,9502022-06-08 HIGH 7.5 CVE-2020-14123 There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, … Miui Mitigation only Fix from $1,9502022-04-22 HIGH 8.8 CVE-2020-14120 Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party applic… Miui No fix yet Fix from $1,9502022-04-21 HIGH 7.5 CVE-2020-14116 An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not verify the validity of the inc… Mi Browser 15.8.0+ Fix from $1,9502022-04-21 MEDIUM 6.1 CVE-2020-14118 An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the… Mi App Store 4.10.0+ Fix from $1,6002022-04-21 MEDIUM 5.5 CVE-2020-14121 A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, an… Mi App Store Mitigation only Fix from $1,6002022-04-21 MEDIUM 5.5 CVE-2020-14122 Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter v… Miui Mitigation only Fix from $1,6002022-04-21 MEDIUM 5.3 CVE-2020-14117 A improper permission configuration vulnerability in Xiaomi Content Center APP. This vulnerability is caused by the lack of correct permission verifi… Content Center 4.4.11+ Fix from $1,6002022-04-21 CRITICAL 9.8 CVE-2020-14115 A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection… Ax3600 Firmware 1.0.67+ Fix from $2,3002022-03-10