Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Brcc CRITICAL 9.8
CVE-2025-45616

Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.

Fix: after 1.2.0
Fix from $2,300 2025-05-05
Ueditor MEDIUM 6.1
CVE-2024-7342

A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/cont…

Fix: after 1.4.3.3
Fix from $1,600 2024-08-01
Ueditor MEDIUM 6.1
CVE-2024-7343

A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor14…

No fix yet
Fix from $1,600 2024-08-01
Ttplayer HIGH 7.8
CVE-2023-48861

DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll.

No fix yet
Fix from $1,950 2023-12-07
Braft HIGH 7.5
CVE-2023-30637

Baidu braft 1.1.2 has a memory leak related to use of the new operator in example/atomic/atomic_server. NOTE: installations with brpc-0.14.0 and late…

No fix yet
Fix from $1,950 2023-04-13
Baidunetdisk MEDIUM 6.7
CVE-2021-36631

Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unsp…

Fix: after 7.4.3
Fix from $1,600 2022-12-22
Kity Minder CRITICAL 9.1
CVE-2022-31830EPSS 16%

Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.

No fix yet
Fix from $2,300 2022-06-09
Ueditor MEDIUM 5.4
CVE-2021-37271

Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information.

No fix yet
Fix from $1,600 2021-09-28
Zrender CRITICAL 9.8
CVE-2021-39227

ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and `clone` helper methods i…

Fix: 5.2.1+
Fix from $2,300 2021-09-17
Xuperchain HIGH 7.5
CVE-2020-22741

An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signatu…

No fix yet
Fix from $1,950 2021-07-19
Umeditor MEDIUM 6.1
CVE-2020-18145

Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php.

No fix yet
Fix from $1,600 2021-07-14
Spark Browser HIGH 7.8
CVE-2018-0692

Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges via a Trojan horse DLL …

Fix: after 43.23.1000.500
Fix from $1,950 2018-11-15
Ueditor MEDIUM 6.1
CVE-2017-14744

UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.

Fix: after 1.4.3.3
Fix from $1,600 2017-09-26
Baidu Ime HIGH 7.8
CVE-2017-2221

Untrusted search path vulnerability in Installer of Baidu IME Ver3.6.1.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in …

Fix: after 3.6.1.6
Fix from $1,950 2017-08-04
Simeji HIGH 7.8
CVE-2017-2219

Untrusted search path vulnerability in the [Simeji for Windows] installer (simeji.exe) allows an attacker to gain privileges via a Trojan horse DLL i…

Mitigation only
Fix from $1,950 2017-06-09
Baidu Navigation MEDIUM 5.4
CVE-2014-7444

The Baidu Navigation (aka com.baidu.navi) application 3.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-…

Mitigation only
Fix from $1,600 2014-10-19
Spark Browser MEDIUM 5.0
CVE-2014-5349

Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) via nested…

No fix yet
Fix from $1,600 2014-08-19
Baidu Hi Im MEDIUM 5.0
CVE-2008-7013

NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response that triggers a divide-b…

Mitigation only
Fix from $1,600 2009-08-19
Baidu Hi HIGH 10.0
CVE-2008-6444EPSS 7%

Stack-based buffer overflow in CSTransfer.dll in Baidu Hi IM might allow remote attackers to execute arbitrary code via a crafted packet, probably re…

Mitigation only
Fix from $1,950 2009-03-09
Soba Search Bar HIGH 9.3
CVE-2007-4105EPSS 7%

A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a …

Patch available
Fix from $1,950 2007-07-31