Skip to content
Noroxi

OpenRefine records

15 published records for vendor openrefine.

All records

15 records
  • Remote Code exec in project import with mysql jdbc url attack

    CriticalCVSS 9.8No exploitEPSS 43%

    openrefine · openrefineSep 15, 2023

  • Butterfly has path/URL confusion in resource handling leading to multiple weaknesses

    CriticalCVSS 9.1No exploitEPSS 2%

    openrefine · butterflyOct 24, 2024

  • OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)

    HighCVSS 8.8No exploitEPSS 1%

    openrefine · openrefineOct 24, 2024

  • OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    openrefine · openrefineOct 24, 2024

  • CVE-2019-3580
    31Monitor

    OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.

    HighCVSS 7.5No exploitEPSS 2%

    openrefine · openrefineJan 2, 2019

  • The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing at

    HighCVSS 7.5No exploitEPSS 2%

    openrefine · openrefineDec 14, 2018

  • Zip slip in OpenRefine

    HighCVSS 7.8No exploitEPSS 1%

    openrefine · openrefineJul 17, 2023

  • OpenRefine JDBC Attack Vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    openrefine · openrefineFeb 12, 2024

  • OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack

    HighCVSS 7.5No exploitEPSS 1%

    openrefine · openrefineSep 15, 2023

  • OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.

    MediumCVSS 6.5Proof of conceptEPSS 2%

    openrefine · openrefineDec 5, 2018

  • OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportRowsCommand

    MediumCVSS 6.9No exploitEPSS 0%

    openrefine · openrefineOct 24, 2024

  • OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, po

    MediumCVSS 6.5Proof of conceptEPSS 1%

    openrefine · openrefineAug 4, 2023

  • OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project

    MediumCVSS 6.1No exploitEPSS 0%

    openrefine · openrefineOct 24, 2024

  • Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)

    MediumCVSS 6.1No exploitEPSS 0%

    openrefine · openrefineOct 24, 2024

  • OpenRefine has a path traversal in LoadLanguageCommand

    MediumCVSS 5.3No exploitEPSS 1%

    openrefine · openrefineOct 24, 2024