Skip to content
Noroxi

eng records

29 published records for vendor eng.

All records

29 records
  • The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

    CriticalCVSS 9.1No exploitEPSS 13%

    eng · spagobiJan 21, 2025

  • In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.

    CriticalCVSS 9.8No exploitEPSS 2%

    eng · knowageSep 5, 2019

  • CVE-2013-6231
    38Monitor

    SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script

    HighCVSS 8.8Proof of conceptEPSS 10%

    eng · spagobiJan 10, 2020

  • Knowage Contains a Remote Code Execution Vulnerability

    CriticalCVSS 9.3No exploitEPSS 1%

    eng · knowageSep 30, 2025

  • A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year'

    HighCVSS 8.8No exploitEPSS 2%

    eng · knowageApr 5, 2021

  • In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in clearte

    HighCVSS 8.8No exploitEPSS 1%

    eng · knowageAug 28, 2019

  • Knowage Server vulnerable to path traversal via upload functionality

    HighCVSS 8.8No exploitEPSS 1%

    eng · knowageAug 4, 2023

  • CVE-2013-6234
    34Monitor

    Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrar

    HighCVSS 8.0Proof of conceptEPSS 7%

    eng · spagobiNov 22, 2019

  • Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' paramet

    MediumCVSS 5.4No exploitEPSS 24%

    eng · knowageMay 12, 2021

  • CVE-2014-7296
    28Monitor

    The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authentic

    MediumCVSS 6.8No exploitEPSS 2%

    eng · spagobiOct 8, 2014

  • Knowage-Server vulnerable to Path traversal in download functionalities

    MediumCVSS 6.5No exploitEPSS 1%

    eng · knowageJul 3, 2023

  • Query injection in Knowage server

    MediumCVSS 6.5No exploitEPSS 1%

    eng · knowageJul 14, 2023

  • Knowage-Server vulnerable to account validation bypass

    MediumCVSS 6.5No exploitEPSS 0%

    eng · knowageJun 23, 2023

  • Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS).

    MediumCVSS 6.1Proof of conceptEPSS 3%

    eng · knowageMay 12, 2021

  • Knowage is vulnerable to blind server-side request forgery (SSRF)

    MediumCVSS 6.3No exploitEPSS 0%

    eng · knowageJan 7, 2026

  • Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS).

    MediumCVSS 6.1No exploitEPSS 1%

    eng · knowageApr 5, 2021

  • In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.

    MediumCVSS 6.1No exploitEPSS 1%

    eng · knowageAug 28, 2019

  • Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.

    MediumCVSS 6.1No exploitEPSS 1%

    eng · knowageJun 13, 2018

  • Improper Neutralization of Alternate XSS Syntax in Knowage-Server

    MediumCVSS 6.1No exploitEPSS 1%

    eng · knowageOct 13, 2022

  • A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel.

    MediumCVSS 6.1No exploitEPSS 0%

    eng · spagobiJan 21, 2025

  • In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token.

    MediumCVSS 5.3No exploitEPSS 1%

    eng · knowageSep 5, 2019

  • Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS).

    MediumCVSS 5.4No exploitEPSS 1%

    eng · knowageApr 5, 2021

  • Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).

    MediumCVSS 5.4No exploitEPSS 1%

    eng · knowageMay 12, 2021

  • SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer functi

    MediumCVSS 5.4No exploitEPSS 1%

    eng · spagobiJan 21, 2025

  • Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).

    MediumCVSS 5.4No exploitEPSS 0%

    eng · knowageMay 12, 2021