Перейти к содержимому
Noroxi

Записи eng

29 опубликованных записей вендора eng.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
17,2 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

29 записей
  • CVE-2024-54794
    40В плане

    The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

    КритическаяCVSS 9,1Эксплойта нетEPSS 13 %

    eng · spagobi21 янв. 2025 г.

  • CVE-2019-13188
    40В плане

    In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    eng · knowage5 сент. 2019 г.

  • CVE-2013-6231
    38Наблюдать

    SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script

    ВысокаяCVSS 8,8Proof of conceptEPSS 10 %

    eng · spagobi10 янв. 2020 г.

  • CVE-2025-59954
    37Наблюдать

    Knowage Contains a Remote Code Execution Vulnerability

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    eng · knowage30 сент. 2025 г.

  • CVE-2021-30055
    35Наблюдать

    A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year'

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    eng · knowage5 апр. 2021 г.

  • CVE-2019-13348
    35Наблюдать

    In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in clearte

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    eng · knowage28 авг. 2019 г.

  • CVE-2023-38702
    35Наблюдать

    Knowage Server vulnerable to path traversal via upload functionality

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    eng · knowage4 авг. 2023 г.

  • CVE-2013-6234
    34Наблюдать

    Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrar

    ВысокаяCVSS 8,0Proof of conceptEPSS 7 %

    eng · spagobi22 нояб. 2019 г.

  • CVE-2021-30214
    28Наблюдать

    Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' paramet

    СредняяCVSS 5,4Эксплойта нетEPSS 24 %

    eng · knowage12 мая 2021 г.

  • CVE-2014-7296
    28Наблюдать

    The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authentic

    СредняяCVSS 6,8Эксплойта нетEPSS 2 %

    eng · spagobi8 окт. 2014 г.

  • CVE-2023-36819
    26Наблюдать

    Knowage-Server vulnerable to Path traversal in download functionalities

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    eng · knowage3 июл. 2023 г.

  • CVE-2023-37472
    26Наблюдать

    Query injection in Knowage server

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    eng · knowage14 июл. 2023 г.

  • CVE-2023-35154
    26Наблюдать

    Knowage-Server vulnerable to account validation bypass

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    eng · knowage23 июн. 2023 г.

  • CVE-2021-30213
    25Наблюдать

    Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS).

    СредняяCVSS 6,1Proof of conceptEPSS 3 %

    eng · knowage12 мая 2021 г.

  • CVE-2025-58441
    25Наблюдать

    Knowage is vulnerable to blind server-side request forgery (SSRF)

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    eng · knowage7 янв. 2026 г.

  • CVE-2021-30058
    24Наблюдать

    Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS).

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    eng · knowage5 апр. 2021 г.

  • CVE-2019-13189
    24Наблюдать

    In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    eng · knowage28 авг. 2019 г.

  • CVE-2018-12355
    24Наблюдать

    Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    eng · knowage13 июн. 2018 г.

  • CVE-2022-39295
    24Наблюдать

    Improper Neutralization of Alternate XSS Syntax in Knowage-Server

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    eng · knowage13 окт. 2022 г.

  • CVE-2024-54792
    24Наблюдать

    A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    eng · spagobi21 янв. 2025 г.

  • CVE-2019-13190
    21Наблюдать

    In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token.

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    eng · knowage5 сент. 2019 г.

  • CVE-2021-30056
    21Наблюдать

    Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS).

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    eng · knowage5 апр. 2021 г.

  • CVE-2021-30212
    21Наблюдать

    Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    eng · knowage12 мая 2021 г.

  • CVE-2024-54795
    21Наблюдать

    SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer functi

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    eng · spagobi21 янв. 2025 г.

  • CVE-2021-30211
    21Наблюдать

    Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    eng · knowage12 мая 2021 г.