CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2025-10184 HIGH

OnePlus OxygenOS Telephony provider permission bypass

CVSS 8.2 EPSS 3.81% Sep 23, 2025
CVE-2023-26309 CRITICAL

A remote code execution vulnerability in the webview component

CVSS 9.8 EPSS 0.76% Aug 10, 2023
CVE-2020-13626 MEDIUM

OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS me…

CVSS 4.6 EPSS 0.32% Oct 9, 2020
CVE-2020-7958 MEDIUM

An issue was discovered on OnePlus 7 Pro devices before 10.0.3.GM21BA. The firmware was found to contain functionality that allows a privileged user (root) in…

CVSS 6.0 EPSS 0.58% Apr 14, 2020
CVE-2017-5947 MEDIUM

An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergenc…

CVSS 6.8 EPSS 0.34% Mar 29, 2018
CVE-2017-11105 CRITICAL

The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with…

CVSS 9.8 EPSS 1.61% Aug 3, 2017
CVE-2017-8851 MEDIUM

An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both products use the…

CVSS 5.9 EPSS 0.45% May 11, 2017
CVE-2017-8850 MEDIUM

An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both ROMs use the…

CVSS 5.9 EPSS 0.43% May 11, 2017
CVE-2017-5948 MEDIUM

An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenient 'updater…

CVSS 5.9 EPSS 0.76% May 11, 2017
CVE-2016-10370 HIGH

An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow f…

CVSS 7.5 EPSS 1.15% May 11, 2017
CVE-2017-5625 MEDIUM

In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arb…

CVSS 4.6 EPSS 0.34% Apr 25, 2017
CVE-2017-5622 MEDIUM

With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious…

CVSS 5.9 EPSS 0.31% Mar 26, 2017
CVE-2017-5623 MEDIUM

An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem b…

CVSS 6.6 EPSS 0.37% Mar 19, 2017
CVE-2017-5626 CRITICAL

OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to lock/unlock the boo…

CVSS 9.8 EPSS 2.82% Mar 12, 2017
CVE-2017-5624 CRITICAL

An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform with dm-ve…

CVSS 9.8 EPSS 2.67% Mar 12, 2017
CVE-2017-5554 HIGH

An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done with…

CVSS 8.1 EPSS 3.00% Jan 23, 2017

Showing 1 to 16 CVEs · page 1