Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-45616 Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request. Brcc after 1.2.0 Fix from $2,3002025-05-05 MEDIUM 6.1 CVE-2024-7342 A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/cont… Ueditor after 1.4.3.3 Fix from $1,6002024-08-01 MEDIUM 6.1 CVE-2024-7343 A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor14… Ueditor No fix yet Fix from $1,6002024-08-01 HIGH 7.8 CVE-2023-48861 DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll. Ttplayer No fix yet Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-30637 Baidu braft 1.1.2 has a memory leak related to use of the new operator in example/atomic/atomic_server. NOTE: installations with brpc-0.14.0 and late… Braft No fix yet Fix from $1,9502023-04-13 MEDIUM 6.7 CVE-2021-36631 Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unsp… Baidunetdisk after 7.4.3 Fix from $1,6002022-12-22 CRITICAL 9.1 CVE-2022-31830EPSS 16% Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php. Kity Minder No fix yet Fix from $2,3002022-06-09 MEDIUM 5.4 CVE-2021-37271 Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information. Ueditor No fix yet Fix from $1,6002021-09-28 CRITICAL 9.8 CVE-2021-39227 ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and `clone` helper methods i… Zrender 5.2.1+ Fix from $2,3002021-09-17 HIGH 7.5 CVE-2020-22741 An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signatu… Xuperchain No fix yet Fix from $1,9502021-07-19 MEDIUM 6.1 CVE-2020-18145 Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php. Umeditor No fix yet Fix from $1,6002021-07-14 HIGH 7.8 CVE-2018-0692 Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges via a Trojan horse DLL … Spark Browser after 43.23.1000.500 Fix from $1,9502018-11-15 MEDIUM 6.1 CVE-2017-14744 UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element. Ueditor after 1.4.3.3 Fix from $1,6002017-09-26 HIGH 7.8 CVE-2017-2221 Untrusted search path vulnerability in Installer of Baidu IME Ver3.6.1.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in … Baidu Ime after 3.6.1.6 Fix from $1,9502017-08-04 HIGH 7.8 CVE-2017-2219 Untrusted search path vulnerability in the [Simeji for Windows] installer (simeji.exe) allows an attacker to gain privileges via a Trojan horse DLL i… Simeji Mitigation only Fix from $1,9502017-06-09 MEDIUM 5.4 CVE-2014-7444 The Baidu Navigation (aka com.baidu.navi) application 3.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-… Baidu Navigation Mitigation only Fix from $1,6002014-10-19 MEDIUM 5.0 CVE-2014-5349 Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) via nested… Spark Browser No fix yet Fix from $1,6002014-08-19 MEDIUM 5.0 CVE-2008-7013 NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response that triggers a divide-b… Baidu Hi Im Mitigation only Fix from $1,6002009-08-19 HIGH 10.0 CVE-2008-6444EPSS 7% Stack-based buffer overflow in CSTransfer.dll in Baidu Hi IM might allow remote attackers to execute arbitrary code via a crafted packet, probably re… Baidu Hi Mitigation only Fix from $1,9502009-03-09 HIGH 9.3 CVE-2007-4105EPSS 7% A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a … Soba Search Bar Patch available Fix from $1,9502007-07-31