Alibaba, Inc.

First CVE: Nov 3, 2021Active for: 5 years
4
CVEs Published
More CVEs Published than 12% of tracked CNAs
2.0
Avg CVEs / Year
More Avg CVEs / Year than 11% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Alibaba, Inc. as a CNA, 50.0% affect products that Alibaba, Inc. develops as a vendor.

50.0%
50.0%
Self-reported: 2Third-party: 2

Of all the CVEs published that affect products developed by Alibaba, Inc., 15.4% are self-published by Alibaba, Inc. as a CNA.

15.4%
84.6%
Self-published: 2Published by other CNAs: 11

Trends Over Time

The number and severity of CVEs published by Alibaba, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 3, 2021
4 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by Alibaba, Inc. as a CNA, regardless of affected vendor or product.

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType e
Jul 23, 20269.039NONO
Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing mod
Apr 15, 20268.327NONO
In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.
Nov 3, 20217.524NONO
: Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet processing module modules) allows : Buffer Manipulation.This
Feb 3, 20266.622NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA4 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (50.0%)
High2 (50.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Alibaba, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Alibaba, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs