Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.8
CVE-2020-8994
An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing the UART interface and then th…
Mdz 25 Dt Firmware
No fix yet
HIGH 8.8
CVE-2019-13322
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0. User interaction …
Mi Browser
10.4.0+
HIGH 8.0
CVE-2019-13321
This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User inte…
Mi Browser
10.4.0+
CRITICAL 9.8
CVE-2019-15913
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communic…
Dgnwg03lm Firmware
No fix yet
HIGH 7.5
CVE-2019-15914
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin pro…
Dgnwg03lm Firmware
No fix yet
HIGH 7.5
CVE-2019-15915
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to…
Dgnwg03lm Firmware
No fix yet
MEDIUM 5.5
CVE-2019-15468
The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/daisy/daisy_sprout:9/PKQ1.180917.001/V10.0.3.0.PDLMIXM:user/release-keys cont…
A2 Lite Firmware
Mitigation only
MEDIUM 5.5
CVE-2019-15469
The Xiaomi Mi Pad 4 Android device with a build fingerprint of Xiaomi/clover/clover:8.1.0/OPM1.171019.019/V9.6.26.0.ODJCNFD:user/release-keys contain…
Pad 4 Firmware
Mitigation only
MEDIUM 5.5
CVE-2019-15470
The Xiaomi Redmi Note 6 Pro Android device with a build fingerprint of xiaomi/tulip/tulip:8.1.0/OPM1.171019.011/V10.2.2.0.OEKMIXM:user/release-keys c…
Redmi Note 6 Pro Firmware
Mitigation only
MEDIUM 5.5
CVE-2019-15471
The Xiaomi Mi Mix 2S Android device with a build fingerprint of Xiaomi/polaris/polaris:8.0.0/OPR1.170623.032/V9.5.19.0.ODGMIFA:user/release-keys cont…
Mix 2s Firmware
Mitigation only
MEDIUM 5.5
CVE-2019-15472
The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/daisy/daisy_sprout:9/PKQ1.180917.001/V10.0.3.0.PDLMIXM:user/release-keys cont…
A2 Lite Firmware
Mitigation only
MEDIUM 5.5
CVE-2019-15473
The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/jasmine/jasmine_sprout:9/PKQ1.180904.001/V10.0.2.0.PDIMIFJ:user/release-keys …
A2 Lite Firmware
Mitigation only
MEDIUM 5.5
CVE-2019-15474
The Xiaomi Cepheus Android device with a build fingerprint of Xiaomi/cepheus/cepheus:9/PKQ1.181121.001/V10.2.6.0.PFAMIXM:user/release-keys contains a…
Cepheus Firmware
Mitigation only
MEDIUM 5.5
CVE-2019-15475
The Xiaomi Mi A3 Android device with a build fingerprint of xiaomi/onc_eea/onc:9/PKQ1.181021.001/V10.2.8.0.PFLEUXM:user/release-keys contains a pre-i…
A3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-18370EPSS 40%
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application us…
Millet Router 3g Firmware
2.28.23+
HIGH 7.5
CVE-2019-18371EPSS 56%
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via…
Millet Router 3g Firmware
2.28.23+
HIGH 7.4
CVE-2019-15843
A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition involving a man-in-the-middle a…
Xiaomi Millet Firmware
Mitigation only
MEDIUM 5.3
CVE-2018-20523EPSS 10%
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a …
Stock Browser
No fix yet
HIGH 8.8
CVE-2019-6743
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Mi6 Browser prior to 10.4.0. User interact…
Mi6 Browser
10.4.0+
MEDIUM 6.5
CVE-2019-12500
The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands …
M365 Firmware
1.5.1+
HIGH 7.5
CVE-2018-20823
The gyroscope on Xiaomi Mi 5s devices allows attackers to cause a denial of service (resonance and false data) via a 20.4 kHz audio signal, aka a MEM…
Mi 5s Firmware
No fix yet
MEDIUM 6.5
CVE-2019-10875
A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5…
Mi Browser
No fix yet
MEDIUM 5.5
CVE-2019-8413
On Xiaomi MIX 2 devices with the 4.4.78 kernel, a NULL pointer dereference in the ioctl interface of the device file /dev/elliptic1 or /dev/elliptic0…
Mi Mix 2 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-18698
An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices. They store cleartext Wi-Fi passwords in logcat …
Xiaomi Mi A1 Firmware
Mitigation only
HIGH 7.5
CVE-2018-19939
The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices throu…
Mi A2 Lite Firmware
after 2018-08-27
HIGH 8.8
CVE-2018-13023EPSS 24%
System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "time…
Miwifi Os
No fix yet
HIGH 8.8
CVE-2018-16130EPSS 24%
System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload…
Miwifi Os
No fix yet
MEDIUM 6.1
CVE-2018-13022
Cross-site scripting vulnerability in the API 404 page on Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary JavaScript via a m…
Miwifi Os
No fix yet
HIGH 7.5
CVE-2018-16307
An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible to induce the application to …
Xiaomi Miwifi Xiaomi 55dd Firmware
No fix yet
CRITICAL 9.8
CVE-2018-14010
OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15, and R3D…
Xiaomi R3p Firmware
2.12.15 / 2.14.5+