Vulnerabilities in vivo

25 results
Vexday analysis

A Vivo registra 23 vulnerabilidades no histórico, com apenas 1 crítica (CVSS) e nenhuma sob ataque ativo conhecido, reduzindo significativamente o risco imediato. O padrão dominante aponta para falhas de autenticação (CWE-306), sendo o dado mais preocupante a publicação de 2 novas vulnerabilidades nos últimos 90 dias, indicando risco recente que merece monitoramento. A ausência de exploração ativa em KEV não invalida a necessidade de revisão dos controles de autenticação nos produtos afetados.

CVE-2020-12483HIGHAppStore Remote Download and Installation VulnerabilityEPSS 0.7%CVE-2024-13186MEDIUMMinigameCenter information leakage vulnerabilityEPSS 0.4%CVE-2024-13173MEDIUMHealth information leakage vulnerabilityEPSS 0.4%CVE-2024-13185MEDIUMMinigameCenter module information leakage vulnerabilityEPSS 0.4%CVE-2021-26277MEDIUMSecurity Advisory | PendingIntent hijacking vulnerability in Framework ServicesEPSS 0.3%CVE-2020-12487HIGHCommand Execution Vulnerability in ABE serviceEPSS 0.3%CVE-2020-12485MEDIUMThe frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the bouEPSS 0.3%CVE-2025-15509HIGHThe SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.EPSS 0.3%CVE-2020-12484MEDIUMWhen using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprisEPSS 0.2%CVE-2021-26278MEDIUMSensitive information leakage vulnerability in wifi moduleEPSS 0.2%CVE-2025-5719MEDIUMThe wallet has an authentication bypass vulnerability that allows access to specific pages.EPSS 0.2%CVE-2024-46939LOWGame Extension Engine Path Traversal VulnerabilityEPSS 0.2%CVE-2020-12488MEDIUMBroken Access Control Vulnerability in Jovi Smart SceneEPSS 0.2%CVE-2020-12491MEDIUMFramework Information Disclosure VulnerabilityEPSS 0.2%CVE-2021-26281MEDIUMInformation disclosure vulnerability in Alarm clock moduleEPSS 0.2%CVE-2025-15515MEDIUMThe authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a loEPSS 0.2%CVE-2026-12058MEDIUMThe connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.EPSS 0.2%CVE-2020-12492LOWWifi information acquisition vulnerability in Framework ServicesEPSS 0.2%CVE-2021-26279MEDIUMInformation disclosure vulnerability in Weather moduleEPSS 0.2%CVE-2021-26280HIGHPermission bypass vulnerability in permission manager moduleEPSS 0.2%