Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · mi

mi

· 15 Critical

Total CVEs

101

Critical

15

Products

148

Search All CVEs →

101

Products (148)

miui9 CVEsax36007 CVEsax3600 firmware6 CVEsxiaomi r3600 firmware5 CVEsxiaomi r36005 CVEsax1800 firmware4 CVEsrm1800 firmware4 CVEsrm18004 CVEsmi browser4 CVEsax18004 CVEsdgnwg03lm3 CVEsdgnwg03lm firmware3 CVEsa2 lite firmware3 CVEsredmi 6 firmware3 CVEsmccgq01lm3 CVEsmccgq01lm firmware3 CVEsmiwifi os3 CVEsredmi 63 CVEszncz03lm3 CVEsxiaomi router ax3200 firmware3 CVEsmi router 33 CVEsxiaomi router ax32003 CVEszncz03lm firmware3 CVEsa2 lite3 CVEsxiaomi3 CVEsrtcgq01lm firmware3 CVEsrtcgq01lm3 CVEsmi app store2 CVEsax90002 CVEsax9000 firmware2 CVEsgetapps2 CVEsmi6 browser2 CVEsmi 102 CVEsmillet router 3g2 CVEsmillet router 3g firmware2 CVEsmiui firmware2 CVEsmix 2s2 CVEsmix 2s firmware2 CVEsredmi ax6s2 CVEsredmi ax6s firmware2 CVEsredmi note 6 pro2 CVEsredmi note 6 pro firmware2 CVEswsdcgq01lm2 CVEswsdcgq01lm firmware2 CVEsxiaomi 13 pro2 CVEsxiaomi 13 pro firmware2 CVEsxiaomi r3d2 CVEsxiaomi r3d firmware2 CVEsxiaomi router firmware2 CVEsxiaomi xiaoai speaker pro lx062 CVEsxiaomi xiaoai speaker pro lx06 firmware2 CVEsmix1 CVEsax6000 firmware1 CVEsax60001 CVEsmix firmware1 CVEsnote 21 CVEsnote 2 firmware1 CVEspad 41 CVEspad 4 firmware1 CVEsr36001 CVEsr3600 firmware1 CVEsredmi 4a1 CVEsredmi 4a firmware1 CVEsredmi 51 CVEsredmi 5 firmware1 CVEsredmi 5 plus1 CVEsredmi 5 plus firmware1 CVEsmdz-25-dt1 CVEsm365 firmware1 CVEsredmi 6 pro1 CVEsredmi 6 pro firmware1 CVEsredmi 6a1 CVEsredmi 6a firmware1 CVEsredmi 71 CVEsredmi 7 firmware1 CVEsredmi 7a1 CVEsredmi 7a firmware1 CVEsredmi ax61 CVEsredmi ax6 firmware1 CVEsxiaomi r3c1 CVEsxiaomi r3c firmware1 CVEsredmi go1 CVEsredmi go firmware1 CVEsredmi k201 CVEsredmi k20 firmware1 CVEsredmi k20 pro1 CVEsredmi k20 pro firmware1 CVEsredmi k401 CVEsredmi note 10 pro1 CVEsredmi note 111 CVEsredmi note 41 CVEsredmi note 4 firmware1 CVEsredmi note 51 CVEsredmi note 5 firmware1 CVEsredmi note 5 pro1 CVEsredmi note 5 pro firmware1 CVEsredmi note 5a prime1 CVEsredmi note 5a prime firmware1 CVEs5s plus firmware1 CVEsa31 CVEsredmi note 71 CVEsredmi note 7 firmware1 CVEsredmi note 7s1 CVEsredmi note 7s firmware1 CVEsredmi note 9t1 CVEsredmi s21 CVEsredmi s2 firmware1 CVEsredmi y31 CVEsredmi y3 firmware1 CVEsm3651 CVEsfile manager1 CVEscontent center1 CVEscepheus firmware1 CVEssmarthome1 CVEssound1 CVEsstock browser1 CVEsxiaomi r3p1 CVEsxiaomi r3p firmware1 CVEscepheus1 CVEsapp market1 CVEsa3 firmware1 CVEsxiaomi ai speaker1 CVEsxiaomi ai speaker firmware1 CVEsxiaomi cloud1 CVEsxiaomi lamp 11 CVEsxiaomi lamp 1 firmware1 CVEsxiaomi mi-a11 CVEsxiaomi mi-a1 firmware1 CVEsxiaomi millet firmware1 CVEsxiaomi mirror screen1 CVEsmi 5s plus firmware1 CVEsmi a2 lite1 CVEsmi a2 lite firmware1 CVEs5s plus1 CVEsmi 5s plus1 CVEsmi mix 21 CVEsmi mix 2 firmware1 CVEsmi 5s firmware1 CVEsmi true wireless earbuds basic 21 CVEsmi true wireless earbuds basic 2 firmware1 CVEsmijia inkjet printer1 CVEsmijia inkjet printer firmware1 CVEsxiaomi miwifi xiaomi 55dd1 CVEsxiaomi miwifi xiaomi 55dd firmware1 CVEsmint browser1 CVEsmi 5s1 CVEsxiaomi r31 CVEsmdz-25-dt firmware1 CVEs

Recent Vulnerabilities

View all 101
CVE-2024-45348MEDIUM 6.4

Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary code.

CVE-2023-26324HIGH 8.8

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

CVE-2023-26323HIGH 7.6

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.

CVE-2023-26322HIGH 8.8

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

CVE-2023-26321MEDIUM 6.3

A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file.

CVE-2023-26315MEDIUM 6.5

The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.

CVE-2024-37664MEDIUM 5.2

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.

CVE-2024-37663MEDIUM 4.1

Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.

CVE-2024-4406CRITICAL 9.6

Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the integral-dialog-page.html file. When parsing the integralInfo parameter, the process does not properly sanitize user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22332.

CVE-2024-4405CRITICAL 9.6

Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the manual-upgrade.html file. When parsing the manualUpgradeInfo parameter, the process does not properly sanitize user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22379.

CVE-2023-26320HIGH 7.5

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.

CVE-2023-26319MEDIUM 6.7

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.

CVE-2023-26318MEDIUM 6.7

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers.

CVE-2023-26317HIGH 7.0

Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing.

CVE-2023-26316MEDIUM 6.1

A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.

CVE-2020-14140HIGH 7.5

When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.

CVE-2020-14131CRITICAL 9.8

The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life.

CVE-2020-14129CRITICAL 9.8

A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege.

CVE-2020-14126HIGH 7.5

Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.

CVE-2020-14114HIGH 7.5

information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.

CVE-2020-14127HIGH 7.5

A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow and can be exploited by attackers to make remote denial of service.

CVE-2022-31277HIGH 8.8

Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request.

CVE-2020-14125HIGH 7.5

A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited by attackers to make denial of service.

CVE-2020-14123HIGH 7.5

There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module crashing and affecting normal functionality, and if successfully exploited the vulnerability can cause elevation of privileges.

CVE-2020-14122MEDIUM 5.5

Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter verification, resulting in user information leakage.