Alibaba records
12 published records for vendor alibaba.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-190 Integer Overflow or Wraparound1
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-290 Authentication Bypass by Spoofing1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2021-29441Proof of concept | Authentication bypassalibaba · nacos · CWE-290 | Critical9.8 | — | 83.5% | Apr 27, 2021 |
51Plan | CVE-2017-18349Proof of concept | parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbipippo · pippo · CWE-20 | Critical9.8 | — | 39.2% | Oct 23, 2018 |
50Plan | CVE-2021-29442Proof of concept | Authentication bypassalibaba · nacos · CWE-306 | High7.5 | — | 65.7% | Apr 27, 2021 |
45Plan | CVE-2022-25845Proof of concept | Deserialization of Untrusted Dataalibaba · fastjson · CWE-502 | Critical9.8 | — | 18.7% | Jun 10, 2022 |
37Monitor | CVE-2021-43116Proof of concept | An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packalibaba · nacos · CWE-287 | High8.8 | — | 7.5% | Jul 5, 2022 |
33Monitor | CVE-2024-44067No exploit | The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivilegedCWE-119 | High8.4 | — | 0.2% | Aug 18, 2024 |
30Monitor | CVE-2021-33800No exploit | In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.alibaba · druid · CWE-22 | High7.5 | — | 1.5% | Nov 3, 2021 |
30Monitor | CVE-2020-21699No exploit | The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in thealibaba · tengine · CWE-190 | High7.5 | — | 0.8% | Aug 22, 2023 |
28Monitor | CVE-2007-0827Proof of concept | The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invalibaba · alipay activex control | Medium6.8 | — | 4.3% | Feb 7, 2007 |
24Monitor | CVE-2021-44667Proof of concept | A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.alibaba · nacos · CWE-79 | Medium6.1 | — | 0.8% | Mar 11, 2022 |
21Monitor | CVE-2020-19676No exploit | Nacos 1.1.4 is affected by: Incorrect Access Control.alibaba · nacos | Medium5.3 | — | 1.4% | Sep 30, 2020 |
21Monitor | CVE-2014-5976No exploit | The alibaba (aka com.alibaba.wireless) application 4.1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows manalibaba · alibaba · CWE-310 | Medium5.4 | — | 0.3% | Sep 20, 2014 |
- CVE-2021-2944164This week
Authentication bypass
CriticalCVSS 9.8Proof of conceptEPSS 83%alibaba · nacosApr 27, 2021
- CVE-2017-1834951Plan
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbi
CriticalCVSS 9.8Proof of conceptEPSS 39%pippo · pippoOct 23, 2018
- CVE-2021-2944250Plan
Authentication bypass
HighCVSS 7.5Proof of conceptEPSS 66%alibaba · nacosApr 27, 2021
- CVE-2022-2584545Plan
Deserialization of Untrusted Data
CriticalCVSS 9.8Proof of conceptEPSS 19%alibaba · fastjsonJun 10, 2022
- CVE-2021-4311637Monitor
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture pack
HighCVSS 8.8Proof of conceptEPSS 7%alibaba · nacosJul 5, 2022
- CVE-2024-4406733Monitor
The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivileged
HighCVSS 8.4No exploitEPSS 0%Aug 18, 2024
- CVE-2021-3380030Monitor
In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.
HighCVSS 7.5No exploitEPSS 2%alibaba · druidNov 3, 2021
- CVE-2020-2169930Monitor
The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the
HighCVSS 7.5No exploitEPSS 1%alibaba · tengineAug 22, 2023
- CVE-2007-082728Monitor
The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that inv
MediumCVSS 6.8Proof of conceptEPSS 4%alibaba · alipay activex controlFeb 7, 2007
- CVE-2021-4466724Monitor
A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.
MediumCVSS 6.1Proof of conceptEPSS 1%alibaba · nacosMar 11, 2022
- CVE-2020-1967621Monitor
Nacos 1.1.4 is affected by: Incorrect Access Control.
MediumCVSS 5.3No exploitEPSS 1%alibaba · nacosSep 30, 2020
- CVE-2014-597621Monitor
The alibaba (aka com.alibaba.wireless) application 4.1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man
MediumCVSS 5.4No exploitEPSS 0%alibaba · alibabaSep 20, 2014