Amaze File Manager Project maintains a file-management application for Android devices with a focused vulnerability exposure centered on OS command injection flaws. The observed weakness reflects the risks inherent to file-system interaction and command execution contexts, where improper input neutralization can enable unintended system-level operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amaze File Manager Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35173CRITICAL The Amaze File Manager application before 3.4.2 for Android does not properly restrict intents for controlling the FTP server (aka services.ftpservice.FTPReceiver.ACTION_START_FTPS | Dec 30, 2020 | 9.8 | 28 | NO | NO |
CVE-2020-36246HIGH Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link. | Feb 19, 2021 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amaze File Manager Project.
Media articles that mention a CVE ID that affects a product developed by Amaze File Manager Project — matched by CVE ID, not by vendor name.