VYPR

Vendor CVEs

LG

All CVEs

139 total · sorted by risk
  • CVE-2018-16946HigSep 12, 2018
    risk 0.52cvss 7.5epss 0.07

    LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials…

  • CVE-2023-40516HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    LG Simple Editor Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of LG Simple Editor. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2022-45422HigNov 21, 2022
    risk 0.51cvss 7.8epss 0.00

    When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-HOT-220005.

  • CVE-2022-23731HigMar 11, 2022
    risk 0.51cvss 7.8epss 0.01

    V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.

  • CVE-2022-23727HigJan 28, 2022
    risk 0.51cvss 7.8epss 0.00

    There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege

  • CVE-2020-35555HigDec 18, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 10 software. When a dual-screen configuration is supported, the device does not lock upon disconnection of a call with the cover closed. The LG ID is LVE-SMP-200027 (December 2020).

  • CVE-2020-35554HigDec 18, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. There is a WebView SSL error-handler vulnerability. The LG ID is LVE-SMP-200026 (December 2020).

  • CVE-2020-25060HigAug 31, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Local users can gain privileges because of LAF and SBL1 flaws. The LG ID is LVE-SMP-200015 (July 2020).

  • CVE-2020-13842HigJun 5, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT command was made available even though it is unused. The LG ID is LVE-SMP-200010 (June 2020).

  • CVE-2020-12754HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A crafted application can obtain control of device input via the window system service. The LG ID is LVE-SMP-170011 (May 2020).

  • CVE-2019-20781HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur.

  • CVE-2020-11875HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK kernel does not properly implement exception handling, allowing an attacker to gain privileges. The LG ID is LVE-SMP-200001 (February 2020).

  • CVE-2019-20773HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. Unprivileged applications can execute shell commands via the connectivity service. The LG ID is LVE-SMP-190008 (August 2019).

  • CVE-2019-20770HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 9.0 software. The HAL service has a buffer overflow that leads to arbitrary code execution. The LG ID is LVE-SMP-190013 (September 2019).

  • CVE-2019-20769HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in the current working directory. The LG ID is LVE-MOT-190001 (November 2019).

  • CVE-2018-16706HigSep 14, 2018
    risk 0.51cvss 7.5epss 0.20

    LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.

  • CVE-2018-9364HigNov 19, 2024
    risk 0.49cvss 7.5epss 0.00

    In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User interaction is not needed for exploitation.

  • CVE-2023-40517HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.03

    LG SuperSign Media Editor ContentRestController getObject Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG SuperSign Media Editor. Authentication is not required…

  • CVE-2023-40515HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    LG Simple Editor joinAddUser Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability.…

  • CVE-2023-40511HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    LG Simple Editor checkServer Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2023-40510HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    LG Simple Editor getServerSetting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2023-40507HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this…

  • CVE-2023-40506HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this…

  • CVE-2023-40503HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    LG Simple Editor saveXmlFile XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this…

  • CVE-2023-4616HigSep 4, 2023
    risk 0.49cvss 7.5epss 0.02

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/thumbnail endpoint. The issue results from the lack…

  • CVE-2023-4615HigSep 4, 2023
    risk 0.49cvss 7.5epss 0.02

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/download/updateFile endpoint. The issue results from…

  • CVE-2020-28345HigNov 8, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 10 software. The Wi-Fi subsystem may crash because of the lack of a NULL parameter check. The LG ID is LVE-SMP-200025 (November 2020).

  • CVE-2020-28344HigNov 8, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. System services may crash because of the lack of a NULL parameter check. The LG ID is LVE-SMP-200024 (November 2020).

  • CVE-2020-26598HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management component could allow an unauthorized actor to kill a TCP connection. The LG ID is LVE-SMP-200023 (October 2020).

  • CVE-2020-26597HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 9.0 and 10 software. The Wi-Fi subsystem has incorrect input validation, leading to a crash. The LG ID is LVE-SMP-200022 (October 2020).

  • CVE-2020-25281HigSep 11, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Applications with sensitive security settings (such as the package verifier application) mishandle unknown-source installations. The LG ID is LVE-SMP-190002 (September 2020).

  • CVE-2020-25065HigAug 31, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Key logging may occur because of an obsolete API. The LG ID is LVE-SMP-170010 (August 2020).

  • CVE-2020-25064HigAug 31, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Certain automated testing is mishandled. The LG ID is LVE-SMP-200019 (August 2020).

  • CVE-2020-25063HigAug 31, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. An application crash can occur because of incorrect application-level input validation. The LG ID is LVE-SMP-200018 (July 2020).

  • CVE-2020-25059HigAug 31, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A service crash may occur because of incorrect input validation. The LG ID is LVE-SMP-200013 (July 2020).

  • CVE-2020-11874HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. Attackers can bypass Factory Reset Protection (FRP). The LG ID is LVE-SMP-200004 (March 2020).

  • CVE-2019-20771HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. WapService allows unconfirmed configuration changes via a modified OMACP message. The LG ID is LVE-SMP-190006 (August 2019).

  • CVE-2019-7404HigMay 13, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var/gapm7100_${today's_date}.log for reading a filename such as gapm7100_190101.log.

  • CVE-2023-6317HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.01

    A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN.  Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA …

  • CVE-2025-10204HigSep 14, 2025
    risk 0.46cvss —epss 0.00

    A vulnerability has been discovered in AC Smart II where passwords can be changed without authorization. This page contains a hidden form for resetting the administrator password. The attacker can manipulate the page using developer tools to display and use the form. This…

  • CVE-2021-30162HigApr 6, 2021
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS services to bypass access control on specific content providers. The LG ID is LVE-SMP-210003 (April 2021).

  • CVE-2019-8372HigFeb 18, 2019
    risk 0.46cvss 7.0epss 0.01

    The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests and elevate system privileges. This occurs because the device object has an…

  • CVE-2016-3846HigAug 5, 2016
    risk 0.46cvss 7.0epss 0.01

    The Serial Peripheral Interface driver in Android before 2016-08-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 28817378.

  • CVE-2021-27901MedMar 2, 2021
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 11 software. They mishandle fingerprint recognition because local high beam mode (LHBM) does not function properly during bright illumination. The LG ID is LVE-SMP-210001 (March 2021).

  • CVE-2019-20785MedApr 17, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 8.0 and 8.1 software for the DTAG carrier. RILD in the radio layer uses an uninitialized variable. The LG ID is LVE-SMP-180013 (January 2019).

  • CVE-2023-40514MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.03

    LG Simple Editor FileManagerController getImageByFilename Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Although authentication is required to…

  • CVE-2023-40513MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.03

    LG Simple Editor UserManageController getImageByFilename Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Although authentication is required to…

  • CVE-2023-40512MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.03

    LG Simple Editor PlayerController getImageByFilename Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Although authentication is required to…

  • CVE-2024-1885MedFeb 26, 2024
    risk 0.41cvss 6.3epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.

  • CVE-2024-6179MedJun 20, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.