OPPO records
18 published records for vendor oppo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-787 Out-of-bounds Write4
- CWE-280 Improper Handling of Insufficient Permissions or Privileges1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-23 Relative Path Traversal1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
- CWE-908 Use of Uninitialized Resource1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-23247No exploit | A command injection vulerability found in quick game engine allows arbitrary remote code in quick app.oppo · quick app · CWE-77 | Critical9.8 | — | 1.8% | Apr 1, 2022 |
39Monitor | CVE-2020-11830No exploit | QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0.oppo · qualityprotect | Critical9.8 | — | 1.5% | Nov 19, 2020 |
39Monitor | CVE-2020-11831No exploit | OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1.oppo · ovoicemanager · CWE-732 | Critical9.8 | — | 1.4% | Nov 19, 2020 |
39Monitor | CVE-2020-11829No exploit | Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493oppo · coloros | Critical9.8 | — | 1.1% | Nov 19, 2020 |
39Monitor | CVE-2023-26310No exploit | Command Injection In OPPO Serviceoppo · coloros · CWE-88 | Critical9.8 | — | 1.1% | Aug 9, 2023 |
39Monitor | CVE-2023-26311No exploit | A remote code execution vulnerability in the webview component of OPPO Store app.oppo · oppo store | Critical9.8 | — | 0.8% | Aug 10, 2023 |
39Monitor | CVE-2026-22070No exploit | ColorOS Assistant Path Traversal Vulnerabilityoppo · coloros assistant · CWE-23 | Critical9.8 | — | 0.2% | Apr 30, 2026 |
31Monitor | CVE-2021-23244No exploit | ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelisoppo · coloros | High7.8 | — | 0.6% | Dec 27, 2021 |
31Monitor | CVE-2018-14996No exploit | The Oppo F5 Android device with a build fingerprint of OPPO/CPH1723/CPH1723:7.1.1/N6F26Q/1513597833:user/release-keys contains a pre-installoppo · f5 firmware | High7.8 | — | 0.5% | Apr 25, 2019 |
31Monitor | CVE-2021-23243No exploit | In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used.oppo · oppo a12 | High7.8 | — | 0.1% | Sep 27, 2021 |
30Monitor | CVE-2020-11828No exploit | In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), Roppo · coloros · CWE-908 | High7.5 | — | 1.2% | Apr 21, 2020 |
30Monitor | CVE-2021-23246No exploit | In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosuroppo · coloros | High7.5 | — | 1.0% | Mar 11, 2022 |
30Monitor | CVE-2024-1608No exploit | OPPO Usercenter Credit sdkoppo · usercenter credit software development kit · CWE-280 | High7.5 | — | 0.5% | Feb 20, 2024 |
22Monitor | CVE-2020-11834No exploit | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write oppo · reno3 pro firmware · CWE-787 | Medium5.5 | — | 0.3% | Dec 31, 2020 |
22Monitor | CVE-2020-11835No exploit | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_oppo · reno3 pro firmware · CWE-787 | Medium5.5 | — | 0.3% | Dec 31, 2020 |
22Monitor | CVE-2020-11833No exploit | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2650_data_log_write doppo · reno3 pro firmware · CWE-787 | Medium5.5 | — | 0.3% | Dec 31, 2020 |
22Monitor | CVE-2020-11832No exploit | In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_charger.c oppo · reno3 pro firmware · CWE-787 | Medium5.5 | — | 0.3% | Dec 31, 2020 |
22Monitor | CVE-2020-11836No exploit | OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulnerability.oppo · a12 | Medium5.5 | — | 0.1% | Feb 5, 2021 |
- CVE-2021-2324740Plan
A command injection vulerability found in quick game engine allows arbitrary remote code in quick app.
CriticalCVSS 9.8No exploitEPSS 2%oppo · quick appApr 1, 2022
- CVE-2020-1183039Monitor
QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0.
CriticalCVSS 9.8No exploitEPSS 1%oppo · qualityprotectNov 19, 2020
- CVE-2020-1183139Monitor
OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1.
CriticalCVSS 9.8No exploitEPSS 1%oppo · ovoicemanagerNov 19, 2020
- CVE-2020-1182939Monitor
Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493
CriticalCVSS 9.8No exploitEPSS 1%oppo · colorosNov 19, 2020
- CVE-2023-2631039Monitor
Command Injection In OPPO Service
CriticalCVSS 9.8No exploitEPSS 1%oppo · colorosAug 9, 2023
- CVE-2023-2631139Monitor
A remote code execution vulnerability in the webview component of OPPO Store app.
CriticalCVSS 9.8No exploitEPSS 1%oppo · oppo storeAug 10, 2023
- CVE-2026-2207039Monitor
ColorOS Assistant Path Traversal Vulnerability
CriticalCVSS 9.8No exploitEPSS 0%oppo · coloros assistantApr 30, 2026
- CVE-2021-2324431Monitor
ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelis
HighCVSS 7.8No exploitEPSS 1%oppo · colorosDec 27, 2021
- CVE-2018-1499631Monitor
The Oppo F5 Android device with a build fingerprint of OPPO/CPH1723/CPH1723:7.1.1/N6F26Q/1513597833:user/release-keys contains a pre-install
HighCVSS 7.8No exploitEPSS 1%oppo · f5 firmwareApr 25, 2019
- CVE-2021-2324331Monitor
In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used.
HighCVSS 7.8No exploitEPSS 0%oppo · oppo a12Sep 27, 2021
- CVE-2020-1182830Monitor
In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), R
HighCVSS 7.5No exploitEPSS 1%oppo · colorosApr 21, 2020
- CVE-2021-2324630Monitor
In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosur
HighCVSS 7.5No exploitEPSS 1%oppo · colorosMar 11, 2022
- CVE-2024-160830Monitor
OPPO Usercenter Credit sdk
HighCVSS 7.5No exploitEPSS 0%oppo · usercenter credit software development kitFeb 20, 2024
- CVE-2020-1183422Monitor
In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write
MediumCVSS 5.5No exploitEPSS 0%oppo · reno3 pro firmwareDec 31, 2020
- CVE-2020-1183522Monitor
In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_
MediumCVSS 5.5No exploitEPSS 0%oppo · reno3 pro firmwareDec 31, 2020
- CVE-2020-1183322Monitor
In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2650_data_log_write d
MediumCVSS 5.5No exploitEPSS 0%oppo · reno3 pro firmwareDec 31, 2020
- CVE-2020-1183222Monitor
In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_charger.c
MediumCVSS 5.5No exploitEPSS 0%oppo · reno3 pro firmwareDec 31, 2020
- CVE-2020-1183622Monitor
OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulnerability.
MediumCVSS 5.5No exploitEPSS 0%oppo · a12Feb 5, 2021