Записи eng
29 опубликованных записей вендора eng.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 17,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-287 Improper Authentication3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-918 Server-Side Request Forgery (SSRF)2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
29 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2024-54794Эксплойта нет | The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.eng · spagobi · CWE-77 | Критическая9,1 | — | 12,8 % | 21 янв. 2025 г. |
40В плане | CVE-2019-13188Эксплойта нет | In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.eng · knowage · CWE-287 | Критическая9,8 | — | 2,5 % | 5 сент. 2019 г. |
38Наблюдать | CVE-2013-6231Proof of concept | SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP scripteng · spagobi · CWE-269 | Высокая8,8 | — | 9,9 % | 10 янв. 2020 г. |
37Наблюдать | CVE-2025-59954Эксплойта нет | Knowage Contains a Remote Code Execution Vulnerabilityeng · knowage · CWE-94 | Критическая9,3 | — | 0,5 % | 30 сент. 2025 г. |
35Наблюдать | CVE-2021-30055Эксплойта нет | A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year'eng · knowage · CWE-89 | Высокая8,8 | — | 1,6 % | 5 апр. 2021 г. |
35Наблюдать | CVE-2019-13348Эксплойта нет | In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in clearteeng · knowage · CWE-522 | Высокая8,8 | — | 1,5 % | 28 авг. 2019 г. |
35Наблюдать | CVE-2023-38702Эксплойта нет | Knowage Server vulnerable to path traversal via upload functionalityeng · knowage · CWE-22 | Высокая8,8 | — | 1,2 % | 4 авг. 2023 г. |
34Наблюдать | CVE-2013-6234Proof of concept | Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrareng · spagobi · CWE-434 | Высокая8,0 | — | 6,7 % | 22 нояб. 2019 г. |
28Наблюдать | CVE-2021-30214Эксплойта нет | Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameteng · knowage · CWE-74 | Средняя5,4 | — | 23,8 % | 12 мая 2021 г. |
28Наблюдать | CVE-2014-7296Эксплойта нет | The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticeng · spagobi · CWE-94 | Средняя6,8 | — | 1,7 % | 8 окт. 2014 г. |
26Наблюдать | CVE-2023-36819Эксплойта нет | Knowage-Server vulnerable to Path traversal in download functionalitieseng · knowage · CWE-22 | Средняя6,5 | — | 0,8 % | 3 июл. 2023 г. |
26Наблюдать | CVE-2023-37472Эксплойта нет | Query injection in Knowage servereng · knowage · CWE-89 | Средняя6,5 | — | 0,7 % | 14 июл. 2023 г. |
26Наблюдать | CVE-2023-35154Эксплойта нет | Knowage-Server vulnerable to account validation bypasseng · knowage · CWE-287 | Средняя6,5 | — | 0,4 % | 23 июн. 2023 г. |
25Наблюдать | CVE-2021-30213Proof of concept | Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS).eng · knowage · CWE-79 | Средняя6,1 | — | 2,7 % | 12 мая 2021 г. |
25Наблюдать | CVE-2025-58441Эксплойта нет | Knowage is vulnerable to blind server-side request forgery (SSRF)eng · knowage · CWE-918 | Средняя6,3 | — | 0,2 % | 7 янв. 2026 г. |
24Наблюдать | CVE-2021-30058Эксплойта нет | Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS).eng · knowage · CWE-79 | Средняя6,1 | — | 1,0 % | 5 апр. 2021 г. |
24Наблюдать | CVE-2019-13189Эксплойта нет | In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.eng · knowage · CWE-79 | Средняя6,1 | — | 0,9 % | 28 авг. 2019 г. |
24Наблюдать | CVE-2018-12355Эксплойта нет | Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.eng · knowage · CWE-79 | Средняя6,1 | — | 0,8 % | 13 июн. 2018 г. |
24Наблюдать | CVE-2022-39295Эксплойта нет | Improper Neutralization of Alternate XSS Syntax in Knowage-Servereng · knowage · CWE-79 | Средняя6,1 | — | 0,6 % | 13 окт. 2022 г. |
24Наблюдать | CVE-2024-54792Эксплойта нет | A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel.eng · spagobi · CWE-352 | Средняя6,1 | — | 0,3 % | 21 янв. 2025 г. |
21Наблюдать | CVE-2019-13190Эксплойта нет | In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token.eng · knowage · CWE-287 | Средняя5,3 | — | 1,4 % | 5 сент. 2019 г. |
21Наблюдать | CVE-2021-30056Эксплойта нет | Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS).eng · knowage · CWE-79 | Средняя5,4 | — | 0,6 % | 5 апр. 2021 г. |
21Наблюдать | CVE-2021-30212Эксплойта нет | Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).eng · knowage · CWE-79 | Средняя5,4 | — | 0,6 % | 12 мая 2021 г. |
21Наблюдать | CVE-2024-54795Эксплойта нет | SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer functieng · spagobi · CWE-79 | Средняя5,4 | — | 0,5 % | 21 янв. 2025 г. |
21Наблюдать | CVE-2021-30211Эксплойта нет | Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).eng · knowage · CWE-79 | Средняя5,4 | — | 0,5 % | 12 мая 2021 г. |
- CVE-2024-5479440В плане
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
КритическаяCVSS 9,1Эксплойта нетEPSS 13 %eng · spagobi21 янв. 2025 г.
- CVE-2019-1318840В плане
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eng · knowage5 сент. 2019 г.
- CVE-2013-623138Наблюдать
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
ВысокаяCVSS 8,8Proof of conceptEPSS 10 %eng · spagobi10 янв. 2020 г.
- CVE-2025-5995437Наблюдать
Knowage Contains a Remote Code Execution Vulnerability
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %eng · knowage30 сент. 2025 г.
- CVE-2021-3005535Наблюдать
A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year'
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %eng · knowage5 апр. 2021 г.
- CVE-2019-1334835Наблюдать
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in clearte
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %eng · knowage28 авг. 2019 г.
- CVE-2023-3870235Наблюдать
Knowage Server vulnerable to path traversal via upload functionality
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %eng · knowage4 авг. 2023 г.
- CVE-2013-623434Наблюдать
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrar
ВысокаяCVSS 8,0Proof of conceptEPSS 7 %eng · spagobi22 нояб. 2019 г.
- CVE-2021-3021428Наблюдать
Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' paramet
СредняяCVSS 5,4Эксплойта нетEPSS 24 %eng · knowage12 мая 2021 г.
- CVE-2014-729628Наблюдать
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authentic
СредняяCVSS 6,8Эксплойта нетEPSS 2 %eng · spagobi8 окт. 2014 г.
- CVE-2023-3681926Наблюдать
Knowage-Server vulnerable to Path traversal in download functionalities
СредняяCVSS 6,5Эксплойта нетEPSS 1 %eng · knowage3 июл. 2023 г.
- CVE-2023-3747226Наблюдать
Query injection in Knowage server
СредняяCVSS 6,5Эксплойта нетEPSS 1 %eng · knowage14 июл. 2023 г.
- CVE-2023-3515426Наблюдать
Knowage-Server vulnerable to account validation bypass
СредняяCVSS 6,5Эксплойта нетEPSS 0 %eng · knowage23 июн. 2023 г.
- CVE-2021-3021325Наблюдать
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS).
СредняяCVSS 6,1Proof of conceptEPSS 3 %eng · knowage12 мая 2021 г.
- CVE-2025-5844125Наблюдать
Knowage is vulnerable to blind server-side request forgery (SSRF)
СредняяCVSS 6,3Эксплойта нетEPSS 0 %eng · knowage7 янв. 2026 г.
- CVE-2021-3005824Наблюдать
Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS).
СредняяCVSS 6,1Эксплойта нетEPSS 1 %eng · knowage5 апр. 2021 г.
- CVE-2019-1318924Наблюдать
In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %eng · knowage28 авг. 2019 г.
- CVE-2018-1235524Наблюдать
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %eng · knowage13 июн. 2018 г.
- CVE-2022-3929524Наблюдать
Improper Neutralization of Alternate XSS Syntax in Knowage-Server
СредняяCVSS 6,1Эксплойта нетEPSS 1 %eng · knowage13 окт. 2022 г.
- CVE-2024-5479224Наблюдать
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %eng · spagobi21 янв. 2025 г.
- CVE-2019-1319021Наблюдать
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %eng · knowage5 сент. 2019 г.
- CVE-2021-3005621Наблюдать
Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS).
СредняяCVSS 5,4Эксплойта нетEPSS 1 %eng · knowage5 апр. 2021 г.
- CVE-2021-3021221Наблюдать
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).
СредняяCVSS 5,4Эксплойта нетEPSS 1 %eng · knowage12 мая 2021 г.
- CVE-2024-5479521Наблюдать
SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer functi
СредняяCVSS 5,4Эксплойта нетEPSS 1 %eng · spagobi21 янв. 2025 г.
- CVE-2021-3021121Наблюдать
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).
СредняяCVSS 5,4Эксплойта нетEPSS 0 %eng · knowage12 мая 2021 г.