Vulnerability index

Browse CVEs

91 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ax9000 Firmware HIGH 8.8
CVE-2024-45348

Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, …

Fix: 1.0.174+
Fix from $1,950 2024-09-23
File Manager CRITICAL 9.8
CVE-2023-26321

A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltere…

Mitigation only
Fix from $2,300 2024-08-28
Getapps CRITICAL 9.8
CVE-2023-26322

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed…

Fix: 32.0.0.1+
Fix from $2,300 2024-08-28
App Market CRITICAL 9.8
CVE-2023-26323

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by a…

Fix: 4.58.2+
Fix from $2,300 2024-08-28
Getapps CRITICAL 9.8
CVE-2023-26324

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed…

Fix: 30.6.0.2+
Fix from $2,300 2024-08-28
Ax9000 Firmware HIGH 8.8
CVE-2023-26315EPSS 19%

The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allo…

Fix: 1.0.174+
Fix from $1,950 2024-08-26
Redmi Ax6s Firmware MEDIUM 5.2
CVE-2024-37664

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traf…

No fix yet
Fix from $1,600 2024-06-17
Xiaomi 13 Pro Firmware CRITICAL 9.6
CVE-2024-4405

Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…

Mitigation only
Fix from $2,300 2024-05-02
Xiaomi 13 Pro Firmware CRITICAL 9.6
CVE-2024-4406

Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…

Mitigation only
Fix from $2,300 2024-05-02
Xiaomi Router Ax3200 Firmware HIGH 8.1
CVE-2023-26320

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.

Fix: 2023.2+
Fix from $1,950 2023-10-11
Xiaomi Router Ax3200 Firmware HIGH 7.2
CVE-2023-26319

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.

Fix: 2023.2+
Fix from $1,950 2023-10-11
Xiaomi Router Ax3200 Firmware HIGH 7.2
CVE-2023-26318

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers.

Fix: 2023.2+
Fix from $1,950 2023-10-11
Xiaomi Router Firmware CRITICAL 9.8
CVE-2023-26317

Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external…

Fix: 2023.2+
Fix from $2,300 2023-08-02
Xiaomi Cloud MEDIUM 6.1
CVE-2023-26316

A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allo…

Fix: after 1.12.0.0.25
Fix from $1,600 2023-08-02
Xiaomi Router Firmware HIGH 7.5
CVE-2020-14140

When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is ca…

Fix: 2023.2+
Fix from $1,950 2023-03-29
Xiaomi CRITICAL 9.8
CVE-2020-14129

A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attac…

No fix yet
Fix from $2,300 2022-10-11
Xiaomi CRITICAL 9.8
CVE-2020-14131

The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional sec…

No fix yet
Fix from $2,300 2022-10-11
Smarthome HIGH 7.5
CVE-2020-14114

information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, …

Fix: after 6.4.701
Fix from $1,950 2022-07-22
Sound HIGH 7.5
CVE-2020-14126

Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which ca…

Fix: after 2.2.40
Fix from $1,950 2022-07-22
Miui HIGH 7.5
CVE-2020-14127

A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow and can be exploited by attack…

Fix: 2022.07.01+
Fix from $1,950 2022-07-14
Xiaomi Lamp 1 Firmware HIGH 8.8
CVE-2022-31277

Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and …

No fix yet
Fix from $1,950 2022-06-16
Miui HIGH 7.5
CVE-2020-14125EPSS 7%

A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited…

Fix: 2022.01.26+
Fix from $1,950 2022-06-08
Miui HIGH 7.5
CVE-2020-14123

There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, …

Mitigation only
Fix from $1,950 2022-04-22
Miui HIGH 8.8
CVE-2020-14120

Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party applic…

No fix yet
Fix from $1,950 2022-04-21
Mi Browser HIGH 7.5
CVE-2020-14116

An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not verify the validity of the inc…

Fix: 15.8.0+
Fix from $1,950 2022-04-21
Mi App Store MEDIUM 6.1
CVE-2020-14118

An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the…

Fix: 4.10.0+
Fix from $1,600 2022-04-21
Mi App Store MEDIUM 5.5
CVE-2020-14121

A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, an…

Mitigation only
Fix from $1,600 2022-04-21
Miui MEDIUM 5.5
CVE-2020-14122

Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter v…

Mitigation only
Fix from $1,600 2022-04-21
Content Center MEDIUM 5.3
CVE-2020-14117

A improper permission configuration vulnerability in Xiaomi Content Center APP. This vulnerability is caused by the lack of correct permission verifi…

Fix: 4.4.11+
Fix from $1,600 2022-04-21
Ax3600 Firmware CRITICAL 9.8
CVE-2020-14115

A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection…

Fix: 1.0.67+
Fix from $2,300 2022-03-10