Alibaba
Products
14- 5 CVEs
- 4 CVEs
- 3 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
Recent CVEs
21| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-43116 | Hig | 0.61 | 8.8 | 0.07 | Jul 5, 2022 | An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login. | ||
| CVE-2017-18349 | Cri | 0.60 | 9.8 | 0.39 | Oct 23, 2018 | parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo… | ||
| CVE-2025-70974 | Cri | 0.58 | 10.0 | 0.01 | Jan 9, 2026 | Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection… | ||
| CVE-2026-33359 | Hig | 0.49 | 7.5 | 0.00 | May 11, 2026 | In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected… | ||
| CVE-2020-21699 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests. | ||
| CVE-2021-44139 | Hig | 0.49 | 7.5 | 0.06 | Mar 23, 2022 | Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF). | ||
| CVE-2021-33800 | Hig | 0.49 | 7.5 | 0.01 | Nov 3, 2021 | In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal. | ||
| CVE-2026-6328 | Hig | 0.47 | — | 0.00 | Apr 15, 2026 | Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame handler modules) allows Protocol Manipulation.This issue affects XQUIC: through… | ||
| CVE-2022-25845 | Hig | 0.47 | 8.1 | 0.19 | Jun 10, 2022 | The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If… | ||
| CVE-2026-1788 | Med | 0.43 | — | 0.00 | Feb 3, 2026 | : Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet processing module modules) allows : Buffer Manipulation.This issue affects Xquic Server: through 1.8.3. | ||
| CVE-2020-19676 | Med | 0.35 | 5.3 | 0.01 | Sep 30, 2020 | Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details interface. Then other Nacos service names can be accessed through the service list interface. Service details can then be accessed when not logged in.… | ||
| CVE-2021-44667 | Med | 0.33 | 6.1 | 0.01 | Mar 11, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters. | ||
| CVE-2021-29441 | Hig | 0.06 | 8.6 | 0.70 | Apr 27, 2021 | Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This… | ||
| CVE-2021-29442 | Hig | 0.05 | 8.6 | 0.66 | Apr 27, 2021 | Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove… | ||
| CVE-2007-0827 | 0.03 | — | 0.04 | Feb 7, 2007 | The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid index argument, which is used as an offset for a function call. | |||
| CVE-2000-0626 | 0.03 | — | 0.06 | Jul 18, 2000 | Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request. | |||
| CVE-1999-0885 | 0.03 | — | 0.03 | Nov 3, 1999 | Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL. | |||
| CVE-2026-16723 | Cri | 0.00 | 9.0 | 0.00 | Jul 23, 2026 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. | ||
| CVE-2014-5976 | 0.00 | — | 0.00 | Sep 20, 2014 | The alibaba (aka com.alibaba.wireless) application 4.1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||
| CVE-1999-1444 | 0.00 | — | 0.01 | Dec 31, 1999 | genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext. |
- risk 0.61cvss 8.8epss 0.07
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.
- risk 0.60cvss 9.8epss 0.39
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo…
- risk 0.58cvss 10.0epss 0.01
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection…
- risk 0.49cvss 7.5epss 0.00
In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected…
- risk 0.49cvss 7.5epss 0.01
The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests.
- risk 0.49cvss 7.5epss 0.06
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
- risk 0.49cvss 7.5epss 0.01
In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.
- risk 0.47cvss —epss 0.00
Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame handler modules) allows Protocol Manipulation.This issue affects XQUIC: through…
- risk 0.47cvss 8.1epss 0.19
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If…
- risk 0.43cvss —epss 0.00
: Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet processing module modules) allows : Buffer Manipulation.This issue affects Xquic Server: through 1.8.3.
- risk 0.35cvss 5.3epss 0.01
Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details interface. Then other Nacos service names can be accessed through the service list interface. Service details can then be accessed when not logged in.…
- risk 0.33cvss 6.1epss 0.01
A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.
- risk 0.06cvss 8.6epss 0.70
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This…
- risk 0.05cvss 8.6epss 0.66
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove…
- CVE-2007-0827Feb 7, 2007risk 0.03cvss —epss 0.04
The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid index argument, which is used as an offset for a function call.
- CVE-2000-0626Jul 18, 2000risk 0.03cvss —epss 0.06
Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.
- CVE-1999-0885Nov 3, 1999risk 0.03cvss —epss 0.03
Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.
- risk 0.00cvss 9.0epss 0.00
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
- CVE-2014-5976Sep 20, 2014risk 0.00cvss —epss 0.00
The alibaba (aka com.alibaba.wireless) application 4.1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVE-1999-1444Dec 31, 1999risk 0.00cvss —epss 0.01
genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.