VYPR

Vendor CVEs

Vivvo

All CVEs

26 total · sorted by risk
  • CVE-2026-11535CriJun 12, 2026
    risk 0.61cvss epss 0.00

    An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device.

  • CVE-2020-12483HigMar 23, 2021
    risk 0.53cvss 8.2epss 0.01

    The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters.

  • CVE-2024-13186HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2024-13185HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2024-13173HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2017-17463HigDec 8, 2017
    risk 0.49cvss 7.5epss 0.01

    Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and psk_wepkey fields.

  • CVE-2020-12487HigDec 17, 2024
    risk 0.46cvss 7.0epss 0.00

    Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.

  • CVE-2020-12484MedDec 17, 2024
    risk 0.42cvss 6.4epss 0.00

    When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a carefully constructed wifi with the same name, which can lead to man-in-the-middle attacks.

  • CVE-2021-26278MedDec 17, 2024
    risk 0.41cvss 6.3epss 0.00

    The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.

  • CVE-2018-15000MedApr 25, 2019
    risk 0.41cvss 6.3epss 0.00

    The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.smartshot (versionCode=1, versionName=3.0.0). This app contains an exported service named…

  • CVE-2021-26279MedDec 17, 2024
    risk 0.38cvss 5.9epss 0.00

    Some parameters of the weather module are improperly stored, leaking some sensitive information.

  • CVE-2025-15515MedMar 13, 2026
    risk 0.36cvss 5.5epss 0.00

    The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local network, it can cause data leakage

  • CVE-2021-26277MedFeb 17, 2023
    risk 0.36cvss 5.6epss 0.00

    The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.

  • CVE-2020-12488MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.00

    The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.

  • CVE-2020-12485MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.00

    The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device.

  • CVE-2018-15001MedDec 28, 2018
    risk 0.36cvss 5.5epss 0.00

    The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported activity app component named…

  • CVE-2026-12058MedJun 12, 2026
    risk 0.34cvss epss 0.00

    The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.

  • CVE-2025-5719MedJun 6, 2025
    risk 0.33cvss epss 0.00

    The wallet has an authentication bypass vulnerability that allows access to specific pages.

  • CVE-2024-46941MedJun 6, 2025
    risk 0.31cvss epss 0.00

    SystemUI has an incorrect component protection setting, which allows access to specific information.

  • CVE-2018-15002MedDec 28, 2018
    risk 0.31cvss 4.7epss 0.00

    The Vivo V7 device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys allows any app co-located on the device to set system properties as the com.android.phone user. The com.qualcomm.qti.modemtestmode app (versionCode=25, versionName=7.1.2)…

  • CVE-2025-15509MedFeb 27, 2026
    risk 0.28cvss 4.3epss 0.00

    The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2025-15567LowFeb 27, 2026
    risk 0.21cvss 3.3epss 0.00

    Insufficient protection mechanisms in the Health Module may lead to partial information disclosure.

  • CVE-2024-46939LowNov 28, 2024
    risk 0.16cvss epss 0.00

    The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite local specific files

  • CVE-2009-3787Oct 26, 2009
    risk 0.04cvss epss 0.07

    files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence.

  • CVE-2008-6801May 7, 2009
    risk 0.00cvss epss 0.00

    Cross-site request forgery (CSRF) vulnerability in Vivvo CMS before 4.0.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2009-0466Feb 10, 2009
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Vivvo CMS before 4.1.1 allows remote attackers to inject arbitrary web script or HTML via a URI that triggers a 404 Page Not Found response.