Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2024-45348
Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, …
Ax9000 Firmware
1.0.174+
CRITICAL 9.8
CVE-2023-26321
A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltere…
File Manager
Mitigation only
CRITICAL 9.8
CVE-2023-26322
A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed…
Getapps
32.0.0.1+
CRITICAL 9.8
CVE-2023-26323
A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by a…
App Market
4.58.2+
CRITICAL 9.8
CVE-2023-26324
A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed…
Getapps
30.6.0.2+
HIGH 8.8
CVE-2023-26315EPSS 19%
The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allo…
Ax9000 Firmware
1.0.174+
MEDIUM 5.2
CVE-2024-37664
Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traf…
Redmi Ax6s Firmware
No fix yet
CRITICAL 9.6
CVE-2024-4405
Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…
Xiaomi 13 Pro Firmware
Mitigation only
CRITICAL 9.6
CVE-2024-4406
Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…
Xiaomi 13 Pro Firmware
Mitigation only
HIGH 8.1
CVE-2023-26320
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
Xiaomi Router Ax3200 Firmware
2023.2+
HIGH 7.2
CVE-2023-26319
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
Xiaomi Router Ax3200 Firmware
2023.2+
HIGH 7.2
CVE-2023-26318
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers.
Xiaomi Router Ax3200 Firmware
2023.2+
CRITICAL 9.8
CVE-2023-26317
Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external…
Xiaomi Router Firmware
2023.2+
MEDIUM 6.1
CVE-2023-26316
A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allo…
Xiaomi Cloud
after 1.12.0.0.25
HIGH 7.5
CVE-2020-14140
When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is ca…
Xiaomi Router Firmware
2023.2+
CRITICAL 9.8
CVE-2020-14129
A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attac…
Xiaomi
No fix yet
CRITICAL 9.8
CVE-2020-14131
The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional sec…
Xiaomi
No fix yet
HIGH 7.5
CVE-2020-14114
information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, …
Smarthome
after 6.4.701
HIGH 7.5
CVE-2020-14126
Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which ca…
Sound
after 2.2.40
HIGH 7.5
CVE-2020-14127
A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow and can be exploited by attack…
Miui
2022.07.01+
HIGH 8.8
CVE-2022-31277
Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and …
Xiaomi Lamp 1 Firmware
No fix yet
HIGH 7.5
CVE-2020-14125EPSS 7%
A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited…
Miui
2022.01.26+
HIGH 7.5
CVE-2020-14123
There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, …
Miui
Mitigation only
HIGH 8.8
CVE-2020-14120
Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party applic…
Miui
No fix yet
HIGH 7.5
CVE-2020-14116
An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not verify the validity of the inc…
Mi Browser
15.8.0+
MEDIUM 6.1
CVE-2020-14118
An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the…
Mi App Store
4.10.0+
MEDIUM 5.5
CVE-2020-14121
A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, an…
Mi App Store
Mitigation only
MEDIUM 5.5
CVE-2020-14122
Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter v…
Miui
Mitigation only
MEDIUM 5.3
CVE-2020-14117
A improper permission configuration vulnerability in Xiaomi Content Center APP. This vulnerability is caused by the lack of correct permission verifi…
Content Center
4.4.11+
CRITICAL 9.8
CVE-2020-14115
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection…
Ax3600 Firmware
1.0.67+