Skip to content
Noroxi

dataease records

72 published records for vendor dataease.

All records

72 records
  • DataEase has an unauthorized vulnerability

    CriticalCVSS 9.3Proof of conceptEPSS 44%

    dataease · dataeaseJan 10, 2025

  • Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerability

    HighCVSS 8.2Proof of conceptEPSS 50%

    dataease · dataeaseJun 3, 2025

  • Dataease Mysql Data Source JDBC Connection Parameters Not Verified Leads to Deserialization Vulnerability

    CriticalCVSS 9.8No exploitEPSS 2%

    dataease · dataeaseOct 25, 2022

  • DataEase's H2 datasource has a remote command execution risk

    CriticalCVSS 9.8No exploitEPSS 1%

    dataease · dataeaseSep 23, 2024

  • DataEase data source has deserialization vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    dataease · dataeaseJun 1, 2023

  • An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.

    CriticalCVSS 9.8No exploitEPSS 1%

    dataease · dataeaseJul 22, 2022

  • DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.

    CriticalCVSS 9.8No exploitEPSS 1%

    dataease · dataeaseJul 22, 2022

  • DataEase has a SQL injection vulnerability that can bypass blacklists

    CriticalCVSS 9.8No exploitEPSS 1%

    dataease · dataeaseJul 25, 2023

  • SQL injection vulnerability due to the keyword blacklist for defending against SQL injection will be bypassed

    CriticalCVSS 9.8No exploitEPSS 1%

    dataease · dataeaseMar 24, 2023

  • An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.

    CriticalCVSS 9.8No exploitEPSS 1%

    dataease · dataeaseFeb 7, 2025

  • Dataease arbitrary interface access vulnerability

    CriticalCVSS 9.3Proof of conceptEPSS 1%

    dataease · dataeaseNov 7, 2024

  • Dataease: Redshift JDBC RCE Bypass

    CriticalCVSS 9.3No exploitEPSS 1%

    dataease · dataeaseMar 12, 2026

  • DataEase has a forged JWT token vulnerability

    CriticalCVSS 9.3No exploitEPSS 1%

    dataease · dataeaseNov 13, 2024

  • Dataease PostgreSQL Data Source JDBC Connection Parameters Not Verified Leads to Deserialization Vulnerability

    CriticalCVSS 9.3No exploitEPSS 1%

    dataease · dataeaseOct 11, 2024

  • DataEase SQL Injection Vulnerability

    CriticalCVSS 9.3No exploitEPSS 1%

    dataease · dataeaseMar 12, 2026

  • Dataease Authentication Bypass Vulnerability

    HighCVSS 7.7Proof of conceptEPSS 21%

    dataease · dataeaseJun 3, 2025

  • The Dataease datasource exists deserialization and arbitrary file read vulnerability

    CriticalCVSS 9.1No exploitEPSS 1%

    dataease · dataeaseFeb 28, 2024

  • Dataease H2 JDBC RCE Bypass

    HighCVSS 8.2No exploitEPSS 9%

    dataease · dataeaseAug 25, 2025

  • DataEase AWS redshift data source exists for remote code execution vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    dataease · dataeaseMar 28, 2023

  • In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.

    HighCVSS 8.8No exploitEPSS 1%

    dataease · dataeaseFeb 8, 2022

  • DataEase's DB2 is vulnerable to SSRF

    HighCVSS 8.9No exploitEPSS 1%

    dataease · dataeaseNov 5, 2025

  • Dataease H2 JDBC Connection Remote Code Execution

    HighCVSS 8.9No exploitEPSS 1%

    dataease · dataeaseJun 26, 2025

  • Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.

    HighCVSS 8.8No exploitEPSS 1%

    dataease · dataeaseJul 22, 2022

  • Dataease PostgreSQL & Redshift Data Source JDBC Connection Parameters Bypass Vulnerability

    HighCVSS 8.9No exploitEPSS 1%

    dataease · dataeaseJul 2, 2025

  • DataEase is vulnerable to Oracle JNDI Injection

    HighCVSS 8.9No exploitEPSS 1%

    dataease · dataeaseNov 5, 2025