Didiglobal maintains a narrow focus on infrastructure and data components, primarily through its messaging queue system (DDMQ) and search platform (KnowSearch), which support internal operations and integrations across its services. The observed vulnerability patterns cluster around authentication and authorization failures alongside insecure credential storage, reflecting the access-control and secret-management challenges common to backend data systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Didiglobal over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-10173HIGH A vulnerability has been found in didi DDMQ 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Console Module. The manipula | Oct 20, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-4984MEDIUM A vulnerability was found in didi KnowSearch 0.3.2/0.3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file /api/es/admin/v3/security/user/ | Sep 15, 2023 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Didiglobal.
Media articles that mention a CVE ID that affects a product developed by Didiglobal — matched by CVE ID, not by vendor name.