Vulnerabilities > Netease
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-30 | CVE-2023-47454 | Uncontrolled Search Path Element vulnerability in Netease Cloudmusic 2.10.4 An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory. | 7.8 |
2020-04-02 | CVE-2020-7620 | OS Command Injection vulnerability in Netease Pomelo-Monitor 0.3.5/0.3.6/0.3.7 pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params. | 9.8 |
2019-11-14 | CVE-2019-18954 | Exposure of Resource to Wrong Sphere vulnerability in Netease Pomelo 2.2.5 Pomelo v2.2.5 allows external control of critical state data. | 5.3 |