datagear records
9 published records for vendor datagear.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 44.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-502 Deserialization of Untrusted Data1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-37759Proof of concept | DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Vidatagear · datagear · CWE-74 | Critical9.8 | — | 2.8% | Jun 24, 2024 |
39Monitor | CVE-2023-1571No exploit | DataGear pagingQueryData sql injectiondatagear · datagear · CWE-89 | Critical9.8 | — | 0.9% | Mar 22, 2023 |
36Monitor | CVE-2025-65792No exploit | DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.datagear · datagear · CWE-22 | Critical9.1 | — | 0.5% | Dec 10, 2025 |
24Monitor | CVE-2023-1573No exploit | DataGear Graph Dataset cross site scriptingdatagear · datagear · CWE-79 | Medium6.1 | — | 0.6% | Mar 22, 2023 |
21Monitor | CVE-2023-2042No exploit | DataGear JDBC Server deserializationdatagear · datagear · CWE-502 | Medium5.3 | — | 1.1% | Apr 14, 2023 |
21Monitor | CVE-2023-7299No exploit | DataGear resolveSql sql injectiondatagear · datagear · CWE-74 | Medium5.3 | — | 0.6% | Nov 23, 2024 |
21Monitor | CVE-2024-7552No exploit | DataGear Data Schema Page ConversionSqlParamValueMapper.java evaluateVariableExpression expression language injectiondatagear · datagear · CWE-917 | Medium5.3 | — | 0.6% | Aug 6, 2024 |
21Monitor | CVE-2023-1572No exploit | DataGear Plugin cross site scriptingdatagear · datagear · CWE-79 | Medium5.4 | — | 0.5% | Mar 22, 2023 |
19Monitor | CVE-2023-1772No exploit | DataGear Diagram Type cross site scriptingdatagear · datagear · CWE-79 | Medium4.8 | — | 0.6% | Mar 31, 2023 |
- CVE-2024-3775940Plan
DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Vi
CriticalCVSS 9.8Proof of conceptEPSS 3%datagear · datagearJun 24, 2024
- CVE-2023-157139Monitor
DataGear pagingQueryData sql injection
CriticalCVSS 9.8No exploitEPSS 1%datagear · datagearMar 22, 2023
- CVE-2025-6579236Monitor
DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.
CriticalCVSS 9.1No exploitEPSS 1%datagear · datagearDec 10, 2025
- CVE-2023-157324Monitor
DataGear Graph Dataset cross site scripting
MediumCVSS 6.1No exploitEPSS 1%datagear · datagearMar 22, 2023
- CVE-2023-204221Monitor
DataGear JDBC Server deserialization
MediumCVSS 5.3No exploitEPSS 1%datagear · datagearApr 14, 2023
- CVE-2023-729921Monitor
DataGear resolveSql sql injection
MediumCVSS 5.3No exploitEPSS 1%datagear · datagearNov 23, 2024
- CVE-2024-755221Monitor
DataGear Data Schema Page ConversionSqlParamValueMapper.java evaluateVariableExpression expression language injection
MediumCVSS 5.3No exploitEPSS 1%datagear · datagearAug 6, 2024
- CVE-2023-157221Monitor
DataGear Plugin cross site scripting
MediumCVSS 5.4No exploitEPSS 1%datagear · datagearMar 22, 2023
- CVE-2023-177219Monitor
DataGear Diagram Type cross site scripting
MediumCVSS 4.8No exploitEPSS 1%datagear · datagearMar 31, 2023