Skip to content
Noroxi

Alibaba records

12 published records for vendor alibaba.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
50%
Median publish → KEV
No record has entered KEV

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

12 records
  • CVE-2021-29441
    64This week

    Authentication bypass

    CriticalCVSS 9.8Proof of conceptEPSS 83%

    alibaba · nacosApr 27, 2021

  • parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbi

    CriticalCVSS 9.8Proof of conceptEPSS 39%

    pippo · pippoOct 23, 2018

  • Authentication bypass

    HighCVSS 7.5Proof of conceptEPSS 66%

    alibaba · nacosApr 27, 2021

  • Deserialization of Untrusted Data

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    alibaba · fastjsonJun 10, 2022

  • An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture pack

    HighCVSS 8.8Proof of conceptEPSS 7%

    alibaba · nacosJul 5, 2022

  • The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivileged

    HighCVSS 8.4No exploitEPSS 0%

    Aug 18, 2024

  • In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.

    HighCVSS 7.5No exploitEPSS 2%

    alibaba · druidNov 3, 2021

  • The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the

    HighCVSS 7.5No exploitEPSS 1%

    alibaba · tengineAug 22, 2023

  • CVE-2007-0827
    28Monitor

    The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that inv

    MediumCVSS 6.8Proof of conceptEPSS 4%

    alibaba · alipay activex controlFeb 7, 2007

  • A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    alibaba · nacosMar 11, 2022

  • Nacos 1.1.4 is affected by: Incorrect Access Control.

    MediumCVSS 5.3No exploitEPSS 1%

    alibaba · nacosSep 30, 2020

  • CVE-2014-5976
    21Monitor

    The alibaba (aka com.alibaba.wireless) application 4.1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man

    MediumCVSS 5.4No exploitEPSS 0%

    alibaba · alibabaSep 20, 2014