Alibaba, Inc.
First CVE: Nov 3, 2021Active for: 5 years
4
CVEs Published
More CVEs Published than 12% of tracked CNAs
2.0
Avg CVEs / Year
More Avg CVEs / Year than 11% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Alibaba, Inc. as a CNA, 50.0% affect products that Alibaba, Inc. develops as a vendor.
50.0%
50.0%
Self-reported: 2Third-party: 2
Of all the CVEs published that affect products developed by Alibaba, Inc., 15.4% are self-published by Alibaba, Inc. as a CNA.
15.4%
84.6%
Self-published: 2Published by other CNAs: 11
Trends Over Time
The number and severity of CVEs published by Alibaba, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 3, 2021
4 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by Alibaba, Inc. as a CNA, regardless of affected vendor or product.
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-16723CRITICAL A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType e | Jul 23, 2026 | 9.0 | 39 | NO | NO |
CVE-2026-6328HIGH Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing mod | Apr 15, 2026 | 8.3 | 27 | NO | NO |
CVE-2021-33800HIGH In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal. | Nov 3, 2021 | 7.5 | 24 | NO | NO |
CVE-2026-1788MEDIUM : Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet processing module modules) allows : Buffer Manipulation.This | Feb 3, 2026 | 6.6 | 22 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA4 CVEs
25%
50%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (50.0%)
High2 (50.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (100.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Alibaba, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Alibaba, Inc. as a CNA — matched by CVE ID, not by organization name.