Vendor CVEs
Vivvo
All CVEs
26 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-11535 | Cri | 0.61 | — | 0.00 | Jun 12, 2026 | An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device. | ||
| CVE-2020-12483 | Hig | 0.53 | 8.2 | 0.01 | Mar 23, 2021 | The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters. | ||
| CVE-2024-13186 | Hig | 0.49 | 7.5 | 0.00 | Jan 8, 2025 | The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. | ||
| CVE-2024-13185 | Hig | 0.49 | 7.5 | 0.00 | Jan 8, 2025 | The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. | ||
| CVE-2024-13173 | Hig | 0.49 | 7.5 | 0.00 | Jan 8, 2025 | The health module has insufficient restrictions on loading URLs, which may lead to some information leakage. | ||
| CVE-2017-17463 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2017 | Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and psk_wepkey fields. | ||
| CVE-2020-12487 | Hig | 0.46 | 7.0 | 0.00 | Dec 17, 2024 | Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege. | ||
| CVE-2020-12484 | Med | 0.42 | 6.4 | 0.00 | Dec 17, 2024 | When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a carefully constructed wifi with the same name, which can lead to man-in-the-middle attacks. | ||
| CVE-2021-26278 | Med | 0.41 | 6.3 | 0.00 | Dec 17, 2024 | The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device. | ||
| CVE-2018-15000 | Med | 0.41 | 6.3 | 0.00 | Apr 25, 2019 | The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.smartshot (versionCode=1, versionName=3.0.0). This app contains an exported service named… | ||
| CVE-2021-26279 | Med | 0.38 | 5.9 | 0.00 | Dec 17, 2024 | Some parameters of the weather module are improperly stored, leaking some sensitive information. | ||
| CVE-2025-15515 | Med | 0.36 | 5.5 | 0.00 | Mar 13, 2026 | The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local network, it can cause data leakage | ||
| CVE-2021-26277 | Med | 0.36 | 5.6 | 0.00 | Feb 17, 2023 | The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions. | ||
| CVE-2020-12488 | Med | 0.36 | 5.5 | 0.00 | Nov 10, 2021 | The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission. | ||
| CVE-2020-12485 | Med | 0.36 | 5.5 | 0.00 | Nov 10, 2020 | The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device. | ||
| CVE-2018-15001 | Med | 0.36 | 5.5 | 0.00 | Dec 28, 2018 | The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported activity app component named… | ||
| CVE-2026-12058 | Med | 0.34 | — | 0.00 | Jun 12, 2026 | The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed. | ||
| CVE-2025-5719 | Med | 0.33 | — | 0.00 | Jun 6, 2025 | The wallet has an authentication bypass vulnerability that allows access to specific pages. | ||
| CVE-2024-46941 | Med | 0.31 | — | 0.00 | Jun 6, 2025 | SystemUI has an incorrect component protection setting, which allows access to specific information. | ||
| CVE-2018-15002 | Med | 0.31 | 4.7 | 0.00 | Dec 28, 2018 | The Vivo V7 device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys allows any app co-located on the device to set system properties as the com.android.phone user. The com.qualcomm.qti.modemtestmode app (versionCode=25, versionName=7.1.2)… | ||
| CVE-2025-15509 | Med | 0.28 | 4.3 | 0.00 | Feb 27, 2026 | The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage. | ||
| CVE-2025-15567 | Low | 0.21 | 3.3 | 0.00 | Feb 27, 2026 | Insufficient protection mechanisms in the Health Module may lead to partial information disclosure. | ||
| CVE-2024-46939 | Low | 0.16 | — | 0.00 | Nov 28, 2024 | The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite local specific files | ||
| CVE-2009-3787 | 0.04 | — | 0.07 | Oct 26, 2009 | files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence. | |||
| CVE-2008-6801 | 0.00 | — | 0.00 | May 7, 2009 | Cross-site request forgery (CSRF) vulnerability in Vivvo CMS before 4.0.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |||
| CVE-2009-0466 | 0.00 | — | 0.01 | Feb 10, 2009 | Cross-site scripting (XSS) vulnerability in Vivvo CMS before 4.1.1 allows remote attackers to inject arbitrary web script or HTML via a URI that triggers a 404 Page Not Found response. |
- risk 0.61cvss —epss 0.00
An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device.
- risk 0.53cvss 8.2epss 0.01
The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters.
- risk 0.49cvss 7.5epss 0.00
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
- risk 0.49cvss 7.5epss 0.00
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
- risk 0.49cvss 7.5epss 0.00
The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.
- risk 0.49cvss 7.5epss 0.01
Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and psk_wepkey fields.
- risk 0.46cvss 7.0epss 0.00
Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.
- risk 0.42cvss 6.4epss 0.00
When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a carefully constructed wifi with the same name, which can lead to man-in-the-middle attacks.
- risk 0.41cvss 6.3epss 0.00
The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.
- risk 0.41cvss 6.3epss 0.00
The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.smartshot (versionCode=1, versionName=3.0.0). This app contains an exported service named…
- risk 0.38cvss 5.9epss 0.00
Some parameters of the weather module are improperly stored, leaking some sensitive information.
- risk 0.36cvss 5.5epss 0.00
The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local network, it can cause data leakage
- risk 0.36cvss 5.6epss 0.00
The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.
- risk 0.36cvss 5.5epss 0.00
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.
- risk 0.36cvss 5.5epss 0.00
The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device.
- risk 0.36cvss 5.5epss 0.00
The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported activity app component named…
- risk 0.34cvss —epss 0.00
The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
- risk 0.33cvss —epss 0.00
The wallet has an authentication bypass vulnerability that allows access to specific pages.
- risk 0.31cvss —epss 0.00
SystemUI has an incorrect component protection setting, which allows access to specific information.
- risk 0.31cvss 4.7epss 0.00
The Vivo V7 device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys allows any app co-located on the device to set system properties as the com.android.phone user. The com.qualcomm.qti.modemtestmode app (versionCode=25, versionName=7.1.2)…
- risk 0.28cvss 4.3epss 0.00
The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.
- risk 0.21cvss 3.3epss 0.00
Insufficient protection mechanisms in the Health Module may lead to partial information disclosure.
- risk 0.16cvss —epss 0.00
The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite local specific files
- CVE-2009-3787Oct 26, 2009risk 0.04cvss —epss 0.07
files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence.
- CVE-2008-6801May 7, 2009risk 0.00cvss —epss 0.00
Cross-site request forgery (CSRF) vulnerability in Vivvo CMS before 4.0.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2009-0466Feb 10, 2009risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Vivvo CMS before 4.1.1 allows remote attackers to inject arbitrary web script or HTML via a URI that triggers a 404 Page Not Found response.