Skip to main content

Vendor archive

oppo CVEs

Beta · best-effort

18 CVEs tagged to vendor oppo5 Critical, 8 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-22070

Published Apr 30, 2026

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-26311

Published Aug 10, 2023

A remote code execution vulnerability in the webview component of OPPO Store app.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23247

Published Apr 1, 2022

A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-23246

Published Mar 11, 2022

In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosure.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23244

Published Dec 27, 2021

ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelist is not installed, attacker can disgui…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11836

Published Feb 6, 2021

OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulnerability. The “adb shell getprop ro.vendor.aee.enforcing” or “adb shell getprop…

CVSS 5.5 · Medium

CVE-2020-11831

Published Nov 19, 2020

OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-11830

Published Nov 19, 2020

QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-11829

Published Nov 19, 2020

Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493e40_200722.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-11828

Published Apr 21, 2020

In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitia…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14996

Published Apr 25, 2019

The Oppo F5 Android device with a build fingerprint of OPPO/CPH1723/CPH1723:7.1.1/N6F26Q/1513597833:user/release-keys contains a pre-installed platform app with a package name of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1