Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.42%—ShopxoAIBaidu UeditorAI24/9/202624/9/2026
A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component Ueditor Upload Interface. The manipulation of the argument path_type results in path traversal. It is possible to launch the attack remotely. The…
AplazadaMedia (5.5)0.53%—Baidu UeditorAIFeehicmsAI7/9/202628/9/2026
A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is…
AplazadaMedia (5.3)0.29%—Baidu SEO HE JIAI27/10/202530/9/2026
Missing Authorization vulnerability in 沃之涛 百度站长SEO合集(支持百度/神马/Bing/头条推送) baiduseo allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects 百度站长SEO合集(支持百度/神马/Bing/头条推送): from n/a through <= 2.1.4.
AplazadaAlta (7.1)0.13%—BaidushareAI28/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in cuckoohello 百度分享按钮 baidushare-wp allows Stored XSS.This issue affects 百度分享按钮: from n/a through <= 1.0.6.
AplazadaAlta (7.1)0.23%—I3geek BaiduxzhAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in i3geek BaiduXZH Submit(百度熊掌号) i3geek-baiduxzh allows Reflected XSS.This issue affects BaiduXZH Submit(百度熊掌号): from n/a through <= 1.4.6.
En análisisCrítica (9.8)0.45%—Baidu Brcc5/5/202517/6/2026
Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.
AnalizadaMedia (4.3)0.29%—Honor Baidu17/4/202517/6/2026
Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability.
AplazadaBaja (3.8)0.45%—Baidu AntivirusAI11/2/202517/6/2026
An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.
AplazadaMedia (6.5)0.32%—Beijing Baidu Netcom Science & Technology CO LTD Haokan VideoAI27/1/202517/6/2026
An issue in Beijing Baidu Netcom Science & Technology Co Ltd Haokan Video iOS 7.70.0 allows attackers to access sensitive user information via supplying a crafted link.
AplazadaMedia (6.5)0.32%—Baidu Input MethodAI27/1/202517/6/2026
An issue in Baidu (China) Co Ltd Baidu Input Method (iOS version) v12.6.13 allows attackers to access user information via supplying a crafted link.
AplazadaMedia (6.5)0.32%—Baidu LiteAI27/1/202517/6/2026
An issue in Beijing Baidu Netcom Science & Technology Co Ltd Baidu Lite app (iOS version) 6.40.0 allows attackers to access user information via supplying a crafted link.
AplazadaMedia (6.4)0.36%—WP Baidu MAPAI30/10/202417/6/2026
The WP Baidu Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'baidu_map' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaMedia (5.3)0.45%—Baidu Ueditor1/8/202417/6/2026
A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipulation of the argument source[] leads to cross site scripting. The attack can be initiated remotely. The exploit has…
AnalizadaMedia (5.3)0.45%—Baidu Ueditor1/8/202417/6/2026
A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The…
ModificadaAlta (7.8)0.31%—Baidu Ttplayer7/12/202317/6/2026
DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll.
ModificadaMedia (6.1)0.24%—Baidu-tongji-generator Project Baidu-tongji-generator13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Haoqisir Baidu Tongji generator allows Stored XSS.This issue affects Baidu Tongji generator: from n/a through 1.0.2.
AnalizadaMedia (4.8)0.37%—Baidu-tongji-generator Project Baidu-tongji-generator18/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Haoqisir Baidu Tongji generator plugin <= 1.0.2 versions.
ModificadaMedia (4.8)0.37%—WP Baidu Submit Project WP Baidu Submit3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Include WP BaiDu Submit plugin <= 1.2.1 versions.
ModificadaAlta (7.5)0.73%—Baidu Braft13/4/202317/6/2026
Baidu braft 1.1.2 has a memory leak related to use of the new operator in example/atomic/atomic_server. NOTE: installations with brpc-0.14.0 and later are unaffected.
ModificadaMedia (6.7)0.32%—Baidunetdisk22/12/202217/6/2026
Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaCrítica (9.3)1.5%—Baiduwenkuspider Flaskweb Project Baiduwenkuspider Flaskweb11/7/202217/6/2026
The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.1)16%—Baidu Kity Minder9/6/202217/6/2026
Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.
ModificadaMedia (5.4)0.56%—Baidu Ueditor28/9/202117/6/2026
Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information.
ModificadaCrítica (9.8)1.4%—Baidu Zrender17/9/202117/6/2026
ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and `clone` helper methods in the `src/core/util.ts` module results in prototype pollution. It affects the popular data visualization library Apache ECharts, which uses and exports these two methods…
ModificadaAlta (7.5)0.83%—Baidu Xuperchain19/7/202117/6/2026
An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.