VYPR

Vendor CVEs

Vivvo

All CVEs

28 total · sorted by risk
  • CVE-2026-11535CriJun 12, 2026
    risk 0.61cvss —epss 0.00

    An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device.

  • CVE-2020-12483HigMar 23, 2021
    risk 0.53cvss 8.2epss 0.01

    The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters.

  • CVE-2024-13186HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2024-13185HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2024-13173HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2017-17463HigDec 8, 2017
    risk 0.49cvss 7.5epss 0.01

    Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and psk_wepkey fields.

  • CVE-2020-12487HigDec 17, 2024
    risk 0.46cvss 7.0epss 0.00

    Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.

  • CVE-2020-12484MedDec 17, 2024
    risk 0.42cvss 6.4epss 0.00

    When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a carefully constructed wifi with the same name, which can lead to man-in-the-middle attacks.

  • CVE-2021-26278MedDec 17, 2024
    risk 0.41cvss 6.3epss 0.00

    The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.

  • CVE-2018-15000MedApr 25, 2019
    risk 0.41cvss 6.3epss 0.00

    The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.smartshot (versionCode=1, versionName=3.0.0). This app contains an exported service named…

  • CVE-2021-26279MedDec 17, 2024
    risk 0.38cvss 5.9epss 0.00

    Some parameters of the weather module are improperly stored, leaking some sensitive information.

  • CVE-2025-15515MedMar 13, 2026
    risk 0.36cvss 5.5epss 0.00

    The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local network, it can cause data leakage

  • CVE-2021-26277MedFeb 17, 2023
    risk 0.36cvss 5.6epss 0.00

    The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.

  • CVE-2020-12488MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.00

    The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.

  • CVE-2020-12485MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.00

    The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device.

  • CVE-2018-15001MedDec 28, 2018
    risk 0.36cvss 5.5epss 0.00

    The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported activity app component named…

  • CVE-2026-12058MedJun 12, 2026
    risk 0.34cvss —epss 0.00

    The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.

  • CVE-2025-5719MedJun 6, 2025
    risk 0.33cvss —epss 0.00

    The wallet has an authentication bypass vulnerability that allows access to specific pages.

  • CVE-2024-46941MedJun 6, 2025
    risk 0.31cvss —epss 0.00

    SystemUI has an incorrect component protection setting, which allows access to specific information.

  • CVE-2018-15002MedDec 28, 2018
    risk 0.31cvss 4.7epss 0.00

    The Vivo V7 device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys allows any app co-located on the device to set system properties as the com.android.phone user. The com.qualcomm.qti.modemtestmode app (versionCode=25, versionName=7.1.2)…

  • CVE-2025-15509MedFeb 27, 2026
    risk 0.28cvss 4.3epss 0.00

    The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2025-15567LowFeb 27, 2026
    risk 0.21cvss 3.3epss 0.00

    Insufficient protection mechanisms in the Health Module may lead to partial information disclosure.

  • CVE-2026-15366LowAug 26, 2026
    risk 0.16cvss —epss 0.00

    A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly within the page

  • CVE-2026-15365LowAug 26, 2026
    risk 0.16cvss —epss 0.00

    A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps outside the app.

  • CVE-2024-46939LowNov 28, 2024
    risk 0.16cvss —epss 0.00

    The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite local specific files

  • CVE-2009-3787Oct 26, 2009
    risk 0.04cvss —epss 0.07

    files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence.

  • CVE-2008-6801May 7, 2009
    risk 0.00cvss —epss 0.00

    Cross-site request forgery (CSRF) vulnerability in Vivvo CMS before 4.0.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2009-0466Feb 10, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Vivvo CMS before 4.1.1 allows remote attackers to inject arbitrary web script or HTML via a URI that triggers a 404 Page Not Found response.