Baidu maintains a diverse portfolio of consumer-facing products spanning web editors, browsers, instant messaging, input methods, and navigation services, a combination that represents both broad user exposure and significant attack surface across web, desktop, and embedded contexts. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability. The recurring exposure centers on products such as UEditor, Spark Browser, and Baidu IME, and clusters within weakness classes characteristic of web-application and client-software development: cross-site scripting and input-validation flaws in web-facing components, memory-safety issues in native code, and cleartext storage of sensitive data across the product line. Defenders tracking this vendor should prioritize its widely distributed browser and input-method components as they command large installed bases. Live exploitation status, severity distribution, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Baidu, Inc. over time
Of all the CVEs published by Baidu, Inc. as a CNA, 0.0% affect products that Baidu, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Baidu, Inc., 0.0% are self-published by Baidu, Inc. as a CNA.
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4105HIGH A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a link to download and a file to | Jul 31, 2007 | 9.3 | 36 | NO | YES |
CVE-2022-31830CRITICAL Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php. | Jun 9, 2022 | 9.1 | 35 | NO | NO |
CVE-2021-39227CRITICAL ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and `clone` helper methods in the `src/core/util.ts` module | Sep 17, 2021 | 9.8 | 30 | NO | NO |
CVE-2014-5349MEDIUM Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print Java | Aug 19, 2014 | 5.0 | 29 | NO | YES |
CVE-2009-2970HIGH Stack-based buffer overflow in the GetUiDllVersion function in an ActiveX control in UiCheck.dll before 1.0.0.7 in UiTV UiPlayer, as used in BaiduX and other products, allows remot | Oct 19, 2009 | 9.3 | 29 | NO | NO |
CVE-2008-6444HIGH Stack-based buffer overflow in CSTransfer.dll in Baidu Hi IM might allow remote attackers to execute arbitrary code via a crafted packet, probably related to an improper length val | Mar 9, 2009 | 10.0 | 27 | NO | NO |
CVE-2025-45616CRITICAL Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request. | May 5, 2025 | 9.8 | 26 | NO | NO |
CVE-2018-0692HIGH Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Nov 15, 2018 | 7.8 | 25 | NO | NO |
CVE-2020-22741HIGH An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature. | Jul 19, 2021 | 7.5 | 24 | NO | NO |
CVE-2017-2221HIGH Untrusted search path vulnerability in Installer of Baidu IME Ver3.6.1.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Aug 4, 2017 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Baidu, Inc..
Media articles that mention a CVE ID that affects a product developed by Baidu, Inc. — matched by CVE ID, not by vendor name.