Netease's vulnerability profile centers on a compact portfolio of consumer-facing applications spanning music streaming, cloud storage, email, and media services. The recurring exposure involves access-control and command-injection weaknesses across products such as CloudMusic, CloudAlbum, and Pmail, reflecting the authentication and input-handling demands of networked consumer platforms. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netease over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1385HIGH Unspecified vulnerability in the NetEase WeiboHD (com.netease.wbhd) application 1.0.0 for Android has unknown impact and attack vectors. | Mar 7, 2012 | 10.0 | 29 | NO | NO |
CVE-2012-1384HIGH Unspecified vulnerability in the NetEase Pmail (com.netease.rpmms) application 0.5.0 and 0.5.2 for Android has unknown impact and attack vectors. | Mar 7, 2012 | 10.0 | 29 | NO | NO |
CVE-2012-1383HIGH Unspecified vulnerability in the NetEase Reader (com.netease.pris) application 1.1.2 and 1.2.0 for Android has unknown impact and attack vectors. | Mar 7, 2012 | 10.0 | 28 | NO | NO |
CVE-2012-1382HIGH Unspecified vulnerability in the Youdao Dictionary (com.youdao.dict) application 1.6.1, 2.0.1(2), and 3.0.0(1) for Android has unknown impact and attack vectors. | Mar 7, 2012 | 10.0 | 28 | NO | NO |
CVE-2012-1381HIGH Unspecified vulnerability in the NetEase CloudAlbum (com.netease.cloudalbum) application 2.0.0 and 2.2.0 for Android has unknown impact and attack vectors. | Mar 7, 2012 | 10.0 | 28 | NO | NO |
CVE-2012-1380HIGH Unspecified vulnerability in the NetEaseWeibo (com.netease.wb) application 1.2.1 and 1.2.2 for Android has unknown impact and attack vectors. | Mar 7, 2012 | 10.0 | 28 | NO | NO |
CVE-2020-7620CRITICAL pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params. | Apr 2, 2020 | 9.8 | 24 | NO | NO |
CVE-2023-47454HIGH An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working d | Nov 30, 2023 | 7.8 | 20 | NO | NO |
CVE-2025-45737MEDIUM An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafted IOCTL commands to the NeacSafe64.sys c | Jun 27, 2025 | 6.5 | 19 | NO | NO |
CVE-2019-18954MEDIUM Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/hand | Nov 14, 2019 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netease.
Media articles that mention a CVE ID that affects a product developed by Netease — matched by CVE ID, not by vendor name.