Known Vulnerabilities for products from Baidu

Listed below are 17 of the newest known vulnerabilities associated with the vendor "Baidu".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-31230 json Not Provided 2023-11-13 2026-04-28
CVE-2023-30637 json Baidu braft 1.1.2 has a memory leak related to use of the new operator in example/atomic/atomic_server. NOTE: installations w... 7.5 - HIGH 2023-04-13 2023-04-24
CVE-2022-31830 json Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class... 9.1 - CRITICAL 2022-06-09 2022-06-15
CVE-2021-39227 json ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and ... 9.8 - CRITICAL 2021-09-17 2022-09-10
CVE-2021-37271 json Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user coo... 5.4 - MEDIUM 2021-09-28 2021-10-01
CVE-2021-36631 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 6.7 - MEDIUM 2022-12-22 2023-08-08
CVE-2020-22741 json An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtai... 7.5 - HIGH 2021-07-19 2021-07-28
CVE-2020-18145 json Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php. 6.1 - MEDIUM 2021-07-14 2021-07-16
CVE-2018-0692 json Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges... 7.8 - HIGH 2018-11-15 2018-12-18
CVE-2017-14744 json UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element. 6.1 - MEDIUM 2017-09-26 2017-10-06
CVE-2017-2221 json Untrusted search path vulnerability in Installer of Baidu IME Ver3.6.1.6 and earlier allows an attacker to gain privileges vi... Not Provided 2017-08-04 2025-04-20
CVE-2017-2219 json Untrusted search path vulnerability in the [Simeji for Windows] installer (simeji.exe) allows an attacker to gain privileges ... Not Provided 2017-06-09 2025-04-20
CVE-2014-7444 json The Baidu Navigation (aka com.baidu.navi) application 3.5.0 for Android does not verify X.509 certificates from SSL servers, ... Not Provided 2014-10-19 2026-05-06
CVE-2014-5349 json Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (appli... Not Provided 2014-08-19 2026-05-06
CVE-2009-2970 json Stack-based buffer overflow in the GetUiDllVersion function in an ActiveX control in UiCheck.dll before 1.0.0.7 in UiTV UiPla... Not Provided 2009-10-19 2026-04-23
CVE-2008-7013 json NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response ... Not Provided 2009-08-19 2026-04-23
CVE-2008-6444 json Stack-based buffer overflow in CSTransfer.dll in Baidu Hi IM might allow remote attackers to execute arbitrary code via a cra... Not Provided 2009-03-09 2026-04-23
CVE-2007-4105 json A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via ... Not Provided 2007-07-31 2026-04-23

Known software with vulnerabilities from Baidu

Type Vendor Product Version
ApplicationBaiduBaidu Ime3.6.1.6
ApplicationBaiduBaidu Navigation3.5.0
ApplicationBaiduFis-kernel1.8.0
ApplicationBaiduSimeji1.0.0.7
ApplicationBaiduSpark Browser2.8
ApplicationBaiduUeditor1.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report