Vivo Mobile Communication Co., Ltd.

First CVE: Nov 10, 2020Active for: 6 years
23
CVEs Published
More CVEs Published than 44% of tracked CNAs
3.8
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
5.8
Avg CVSS Score
Higher Avg CVSS Score than 7% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Vivo Mobile Communication Co., Ltd. as a CNA, 30.4% affect products that Vivo Mobile Communication Co., Ltd. develops as a vendor.

30.4%
69.6%
Self-reported: 7Third-party: 16

Of all the CVEs published that affect products developed by Vivo Mobile Communication Co., Ltd., 63.6% are self-published by Vivo Mobile Communication Co., Ltd. as a CNA.

63.6%
36.4%
Self-published: 7Published by other CNAs: 4

Trends Over Time

The number and severity of CVEs published by Vivo Mobile Communication Co., Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2020
5 years ago
Most Recent CVE
Jun 12, 2026
42 days ago

Top CVEs

All CVEs published by Vivo Mobile Communication Co., Ltd. as a CNA, regardless of affected vendor or product.

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device.
Jun 12, 20269.434NONO
The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.
Feb 17, 20239.829NONO
The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
Jun 12, 20265.324NONO
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
Jan 8, 20257.522NONO
The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.
Jan 8, 20257.522NONO
Locally installed application can bypass the permission check and perform system operations that require permission.
Dec 17, 20247.921NONO
The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local network, it can cause data leakage
Mar 13, 20265.520NONO
The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.
Dec 17, 20246.320NONO
The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.
Feb 27, 20264.319NONO
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
Jan 8, 20257.519NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA23 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local12 (52.2%)
Network6 (26.1%)
Unknown0 (0.0%)
Physical2 (8.7%)
Adjacent Network1 (4.3%)
Attack Complexity
Low21 (91.3%)
High2 (8.7%)
Unknown0 (0.0%)
User Interaction
None10 (43.5%)
Unknown0 (0.0%)
Required8 (34.8%)
Privileges Required
Low8 (34.8%)
High0 (0.0%)
None15 (65.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Vivo Mobile Communication Co., Ltd. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Vivo Mobile Communication Co., Ltd. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs