Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.96%—Xiaomi Fileexplorer11/3/202614/7/2026
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows…
AplazadaCrítica (9.1)0.30%—Xiaomi Galaxy FDS SDK AndroidAIApache HttpclientAI12/2/202614/7/2026
Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid…
AplazadaCrítica (9.6)0.28%—Xiaomi MI Connect ServiceAI23/6/202517/6/2026
An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to Unauthorized access to the victim’s device.
AplazadaMedia (6.5)0.17%—Xiaomi MI Connect ServiceAI27/3/202517/6/2026
A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to leak sensitive user information.
AplazadaAlta (7.3)0.15%—Xiaomi Phone FrameworkAI27/3/202517/6/2026
A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by attackers to Access sensitive methods.
AplazadaMedia (5.5)0.15%—Xiaomi Phone FrameworkAI27/3/202517/6/2026
A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by attackers to Access sensitive methods.
AplazadaMedia (4.3)0.21%—Xiaomi Shop ApplicationAI27/3/202517/6/2026
A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
AplazadaMedia (4.3)0.16%—Xiaomi Quick APP FrameworkAI27/3/202517/6/2026
An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is caused by improper input validation and can be exploited by attackers tointent redriction.
AplazadaAlta (8.8)0.29%—Xiaomi SmarthomeAI27/3/202517/6/2026
An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
AplazadaAlta (7.8)0.19%—Xiaomi Game CenterAI26/3/202517/6/2026
A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
AplazadaAlta (8.8)0.47%—Xiaomi Security CenterAITrendmicro Zero DAY InitiativeAI28/8/202417/6/2026
The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe…
AnalizadaCrítica (9.6)2.2%—Xiaomi 13 PRO Firmware2/5/202417/6/2026
Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a…
AnalizadaCrítica (9.6)1.2%—Xiaomi 13 PRO Firmware2/5/202417/6/2026
Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a…
ModificadaAlta (8.1)1.1%—Xiaomi Router Ax3200 Firmware11/10/202317/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
ModificadaAlta (7.2)0.97%—Xiaomi Router Ax3200 Firmware11/10/202317/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
ModificadaAlta (7.2)0.58%—Xiaomi Router Ax3200 Firmware11/10/202317/6/2026
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers.
ModificadaCrítica (9.8)1.1%—Xiaomi Router Firmware2/8/202317/6/2026
Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing.
ModificadaMedia (6.1)0.35%—Xiaomi Cloud2/8/202317/6/2026
A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.
ModificadaAlta (7.5)0.99%—Xiaomi Router Firmware29/3/202317/6/2026
When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command…
ModificadaCrítica (9.8)0.89%—Xiaomi11/10/202217/6/2026
The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life.
ModificadaCrítica (9.8)0.99%—Xiaomi11/10/202217/6/2026
A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege.
ModificadaAlta (8.8)0.56%—Xiaomi Lamp 1 Firmware16/6/202217/6/2026
Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request.
ModificadaAlta (7.5)0.96%—Xiaomi Mirror Screen18/1/202217/6/2026
A stack overflow in the HTTP server of Cast can be exploited to make the app crash in LAN.
ModificadaMedia (5.3)0.71%—Xiaomi16/9/202117/6/2026
Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809
ModificadaCrítica (9.8)1.2%—Xiaomi AI Speaker Firmware11/9/202017/6/2026
Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.