Vulnerabilities > Netease

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2023-47454 Uncontrolled Search Path Element vulnerability in Netease Cloudmusic 2.10.4
An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory.
local
low complexity
netease CWE-427
7.8
2020-04-02 CVE-2020-7620 OS Command Injection vulnerability in Netease Pomelo-Monitor 0.3.5/0.3.6/0.3.7
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
network
low complexity
netease CWE-78
critical
9.8
2019-11-14 CVE-2019-18954 Exposure of Resource to Wrong Sphere vulnerability in Netease Pomelo 2.2.5
Pomelo v2.2.5 allows external control of critical state data.
network
low complexity
netease CWE-668
5.3