Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.42% | — | ShopxoAIBaidu UeditorAI | 24/9/2026 | 24/9/2026 | A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component Ueditor Upload Interface. The manipulation of the argument path_type results in path traversal. It is possible to launch the attack remotely. The… | |
| Aplazada | Media (5.5) | 0.53% | — | Baidu UeditorAIFeehicmsAI | 7/9/2026 | 28/9/2026 | A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is… | |
| Aplazada | Media (5.3) | 0.29% | — | Baidu SEO HE JIAI | 27/10/2025 | 30/9/2026 | Missing Authorization vulnerability in 沃之涛 百度站长SEO合集(支持百度/神马/Bing/头条推送) baiduseo allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects 百度站长SEO合集(支持百度/神马/Bing/头条推送): from n/a through <= 2.1.4. | |
| Aplazada | Alta (7.1) | 0.13% | — | BaidushareAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in cuckoohello 百度分享按钮 baidushare-wp allows Stored XSS.This issue affects 百度分享按钮: from n/a through <= 1.0.6. | |
| Aplazada | Alta (7.1) | 0.23% | — | I3geek BaiduxzhAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in i3geek BaiduXZH Submit(百度熊掌号) i3geek-baiduxzh allows Reflected XSS.This issue affects BaiduXZH Submit(百度熊掌号): from n/a through <= 1.4.6. | |
| En análisis | Crítica (9.8) | 0.45% | — | Baidu Brcc | 5/5/2025 | 17/6/2026 | Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request. | |
| Analizada | Media (4.3) | 0.29% | — | Honor Baidu | 17/4/2025 | 17/6/2026 | Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability. | |
| Aplazada | Baja (3.8) | 0.45% | — | Baidu AntivirusAI | 11/2/2025 | 17/6/2026 | An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack. | |
| Aplazada | Media (6.5) | 0.32% | — | Beijing Baidu Netcom Science & Technology CO LTD Haokan VideoAI | 27/1/2025 | 17/6/2026 | An issue in Beijing Baidu Netcom Science & Technology Co Ltd Haokan Video iOS 7.70.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (6.5) | 0.32% | — | Baidu Input MethodAI | 27/1/2025 | 17/6/2026 | An issue in Baidu (China) Co Ltd Baidu Input Method (iOS version) v12.6.13 allows attackers to access user information via supplying a crafted link. | |
| Aplazada | Media (6.5) | 0.32% | — | Baidu LiteAI | 27/1/2025 | 17/6/2026 | An issue in Beijing Baidu Netcom Science & Technology Co Ltd Baidu Lite app (iOS version) 6.40.0 allows attackers to access user information via supplying a crafted link. | |
| Aplazada | Media (6.4) | 0.36% | — | WP Baidu MAPAI | 30/10/2024 | 17/6/2026 | The WP Baidu Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'baidu_map' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.3) | 0.45% | — | Baidu Ueditor | 1/8/2024 | 17/6/2026 | A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipulation of the argument source[] leads to cross site scripting. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.45% | — | Baidu Ueditor | 1/8/2024 | 17/6/2026 | A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Modificada | Alta (7.8) | 0.31% | — | Baidu Ttplayer | 7/12/2023 | 17/6/2026 | DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll. | |
| Modificada | Media (6.1) | 0.24% | — | Baidu-tongji-generator Project Baidu-tongji-generator | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Haoqisir Baidu Tongji generator allows Stored XSS.This issue affects Baidu Tongji generator: from n/a through 1.0.2. | |
| Analizada | Media (4.8) | 0.37% | — | Baidu-tongji-generator Project Baidu-tongji-generator | 18/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Haoqisir Baidu Tongji generator plugin <= 1.0.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | WP Baidu Submit Project WP Baidu Submit | 3/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Include WP BaiDu Submit plugin <= 1.2.1 versions. | |
| Modificada | Alta (7.5) | 0.73% | — | Baidu Braft | 13/4/2023 | 17/6/2026 | Baidu braft 1.1.2 has a memory leak related to use of the new operator in example/atomic/atomic_server. NOTE: installations with brpc-0.14.0 and later are unaffected. | |
| Modificada | Media (6.7) | 0.32% | — | Baidunetdisk | 22/12/2022 | 17/6/2026 | Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Crítica (9.3) | 1.5% | — | Baiduwenkuspider Flaskweb Project Baiduwenkuspider Flaskweb | 11/7/2022 | 17/6/2026 | The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.1) | 16% | — | Baidu Kity Minder | 9/6/2022 | 17/6/2026 | Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php. | |
| Modificada | Media (5.4) | 0.56% | — | Baidu Ueditor | 28/9/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information. | |
| Modificada | Crítica (9.8) | 1.4% | — | Baidu Zrender | 17/9/2021 | 17/6/2026 | ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and `clone` helper methods in the `src/core/util.ts` module results in prototype pollution. It affects the popular data visualization library Apache ECharts, which uses and exports these two methods… | |
| Modificada | Alta (7.5) | 0.83% | — | Baidu Xuperchain | 19/7/2021 | 17/6/2026 | An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature. |