eng records
29 published records for vendor eng.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 17.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-287 Improper Authentication3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-918 Server-Side Request Forgery (SSRF)2
The weakness classes this vendor ships most often: where to look.
CWEAll records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-54794No exploit | The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.eng · spagobi · CWE-77 | Critical9.1 | — | 12.8% | Jan 21, 2025 |
40Plan | CVE-2019-13188No exploit | In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.eng · knowage · CWE-287 | Critical9.8 | — | 2.5% | Sep 5, 2019 |
38Monitor | CVE-2013-6231Proof of concept | SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP scripteng · spagobi · CWE-269 | High8.8 | — | 9.9% | Jan 10, 2020 |
37Monitor | CVE-2025-59954No exploit | Knowage Contains a Remote Code Execution Vulnerabilityeng · knowage · CWE-94 | Critical9.3 | — | 0.5% | Sep 30, 2025 |
35Monitor | CVE-2021-30055No exploit | A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year'eng · knowage · CWE-89 | High8.8 | — | 1.6% | Apr 5, 2021 |
35Monitor | CVE-2019-13348No exploit | In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in clearteeng · knowage · CWE-522 | High8.8 | — | 1.5% | Aug 28, 2019 |
35Monitor | CVE-2023-38702No exploit | Knowage Server vulnerable to path traversal via upload functionalityeng · knowage · CWE-22 | High8.8 | — | 1.2% | Aug 4, 2023 |
34Monitor | CVE-2013-6234Proof of concept | Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrareng · spagobi · CWE-434 | High8.0 | — | 6.7% | Nov 22, 2019 |
28Monitor | CVE-2021-30214No exploit | Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameteng · knowage · CWE-74 | Medium5.4 | — | 23.8% | May 12, 2021 |
28Monitor | CVE-2014-7296No exploit | The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticeng · spagobi · CWE-94 | Medium6.8 | — | 1.7% | Oct 8, 2014 |
26Monitor | CVE-2023-36819No exploit | Knowage-Server vulnerable to Path traversal in download functionalitieseng · knowage · CWE-22 | Medium6.5 | — | 0.8% | Jul 3, 2023 |
26Monitor | CVE-2023-37472No exploit | Query injection in Knowage servereng · knowage · CWE-89 | Medium6.5 | — | 0.7% | Jul 14, 2023 |
26Monitor | CVE-2023-35154No exploit | Knowage-Server vulnerable to account validation bypasseng · knowage · CWE-287 | Medium6.5 | — | 0.4% | Jun 23, 2023 |
25Monitor | CVE-2021-30213Proof of concept | Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS).eng · knowage · CWE-79 | Medium6.1 | — | 2.7% | May 12, 2021 |
25Monitor | CVE-2025-58441No exploit | Knowage is vulnerable to blind server-side request forgery (SSRF)eng · knowage · CWE-918 | Medium6.3 | — | 0.2% | Jan 7, 2026 |
24Monitor | CVE-2021-30058No exploit | Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS).eng · knowage · CWE-79 | Medium6.1 | — | 1.0% | Apr 5, 2021 |
24Monitor | CVE-2019-13189No exploit | In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.eng · knowage · CWE-79 | Medium6.1 | — | 0.9% | Aug 28, 2019 |
24Monitor | CVE-2018-12355No exploit | Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.eng · knowage · CWE-79 | Medium6.1 | — | 0.8% | Jun 13, 2018 |
24Monitor | CVE-2022-39295No exploit | Improper Neutralization of Alternate XSS Syntax in Knowage-Servereng · knowage · CWE-79 | Medium6.1 | — | 0.6% | Oct 13, 2022 |
24Monitor | CVE-2024-54792No exploit | A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel.eng · spagobi · CWE-352 | Medium6.1 | — | 0.3% | Jan 21, 2025 |
21Monitor | CVE-2019-13190No exploit | In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token.eng · knowage · CWE-287 | Medium5.3 | — | 1.4% | Sep 5, 2019 |
21Monitor | CVE-2021-30056No exploit | Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS).eng · knowage · CWE-79 | Medium5.4 | — | 0.6% | Apr 5, 2021 |
21Monitor | CVE-2021-30212No exploit | Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).eng · knowage · CWE-79 | Medium5.4 | — | 0.6% | May 12, 2021 |
21Monitor | CVE-2024-54795No exploit | SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer functieng · spagobi · CWE-79 | Medium5.4 | — | 0.5% | Jan 21, 2025 |
21Monitor | CVE-2021-30211No exploit | Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).eng · knowage · CWE-79 | Medium5.4 | — | 0.5% | May 12, 2021 |
- CVE-2024-5479440Plan
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
CriticalCVSS 9.1No exploitEPSS 13%eng · spagobiJan 21, 2025
- CVE-2019-1318840Plan
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
CriticalCVSS 9.8No exploitEPSS 2%eng · knowageSep 5, 2019
- CVE-2013-623138Monitor
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
HighCVSS 8.8Proof of conceptEPSS 10%eng · spagobiJan 10, 2020
- CVE-2025-5995437Monitor
Knowage Contains a Remote Code Execution Vulnerability
CriticalCVSS 9.3No exploitEPSS 1%eng · knowageSep 30, 2025
- CVE-2021-3005535Monitor
A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year'
HighCVSS 8.8No exploitEPSS 2%eng · knowageApr 5, 2021
- CVE-2019-1334835Monitor
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in clearte
HighCVSS 8.8No exploitEPSS 1%eng · knowageAug 28, 2019
- CVE-2023-3870235Monitor
Knowage Server vulnerable to path traversal via upload functionality
HighCVSS 8.8No exploitEPSS 1%eng · knowageAug 4, 2023
- CVE-2013-623434Monitor
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrar
HighCVSS 8.0Proof of conceptEPSS 7%eng · spagobiNov 22, 2019
- CVE-2021-3021428Monitor
Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' paramet
MediumCVSS 5.4No exploitEPSS 24%eng · knowageMay 12, 2021
- CVE-2014-729628Monitor
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authentic
MediumCVSS 6.8No exploitEPSS 2%eng · spagobiOct 8, 2014
- CVE-2023-3681926Monitor
Knowage-Server vulnerable to Path traversal in download functionalities
MediumCVSS 6.5No exploitEPSS 1%eng · knowageJul 3, 2023
- CVE-2023-3747226Monitor
Query injection in Knowage server
MediumCVSS 6.5No exploitEPSS 1%eng · knowageJul 14, 2023
- CVE-2023-3515426Monitor
Knowage-Server vulnerable to account validation bypass
MediumCVSS 6.5No exploitEPSS 0%eng · knowageJun 23, 2023
- CVE-2021-3021325Monitor
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS).
MediumCVSS 6.1Proof of conceptEPSS 3%eng · knowageMay 12, 2021
- CVE-2025-5844125Monitor
Knowage is vulnerable to blind server-side request forgery (SSRF)
MediumCVSS 6.3No exploitEPSS 0%eng · knowageJan 7, 2026
- CVE-2021-3005824Monitor
Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS).
MediumCVSS 6.1No exploitEPSS 1%eng · knowageApr 5, 2021
- CVE-2019-1318924Monitor
In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
MediumCVSS 6.1No exploitEPSS 1%eng · knowageAug 28, 2019
- CVE-2018-1235524Monitor
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.
MediumCVSS 6.1No exploitEPSS 1%eng · knowageJun 13, 2018
- CVE-2022-3929524Monitor
Improper Neutralization of Alternate XSS Syntax in Knowage-Server
MediumCVSS 6.1No exploitEPSS 1%eng · knowageOct 13, 2022
- CVE-2024-5479224Monitor
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel.
MediumCVSS 6.1No exploitEPSS 0%eng · spagobiJan 21, 2025
- CVE-2019-1319021Monitor
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token.
MediumCVSS 5.3No exploitEPSS 1%eng · knowageSep 5, 2019
- CVE-2021-3005621Monitor
Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS).
MediumCVSS 5.4No exploitEPSS 1%eng · knowageApr 5, 2021
- CVE-2021-3021221Monitor
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).
MediumCVSS 5.4No exploitEPSS 1%eng · knowageMay 12, 2021
- CVE-2024-5479521Monitor
SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer functi
MediumCVSS 5.4No exploitEPSS 1%eng · spagobiJan 21, 2025
- CVE-2021-3021121Monitor
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).
MediumCVSS 5.4No exploitEPSS 0%eng · knowageMay 12, 2021