Записи OpenRefine
15 опубликованных записей вендора openrefine.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 86,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-36 Absolute Path Traversal1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-2023-41887Эксплойта нет | Remote Code exec in project import with mysql jdbc url attackopenrefine · openrefine · CWE-89 | Критическая9,8 | — | 42,5 % | 15 сент. 2023 г. |
36Наблюдать | CVE-2024-47883Эксплойта нет | Butterfly has path/URL confusion in resource handling leading to multiple weaknessesopenrefine · butterfly · CWE-36 | Критическая9,1 | — | 1,6 % | 24 окт. 2024 г. |
35Наблюдать | CVE-2024-47881Эксплойта нет | OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)openrefine · openrefine · CWE-89 | Высокая8,8 | — | 0,7 % | 24 окт. 2024 г. |
35Наблюдать | CVE-2024-47879Эксплойта нет | OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)openrefine · openrefine · CWE-94 | Высокая8,8 | — | 0,4 % | 24 окт. 2024 г. |
31Наблюдать | CVE-2019-3580Эксплойта нет | OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.openrefine · openrefine · CWE-22 | Высокая7,5 | — | 1,9 % | 2 янв. 2019 г. |
31Наблюдать | CVE-2018-20157Эксплойта нет | The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing atopenrefine · openrefine · CWE-611 | Высокая7,5 | — | 1,7 % | 14 дек. 2018 г. |
31Наблюдать | CVE-2023-37476Эксплойта нет | Zip slip in OpenRefineopenrefine · openrefine · CWE-22 | Высокая7,8 | — | 0,6 % | 17 июл. 2023 г. |
30Наблюдать | CVE-2024-23833Эксплойта нет | OpenRefine JDBC Attack Vulnerabilityopenrefine · openrefine · CWE-22 | Высокая7,5 | — | 1,0 % | 12 февр. 2024 г. |
30Наблюдать | CVE-2023-41886Эксплойта нет | OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attackopenrefine · openrefine · CWE-89 | Высокая7,5 | — | 1,0 % | 15 сент. 2023 г. |
27Наблюдать | CVE-2018-19859Proof of concept | OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.openrefine · openrefine · CWE-22 | Средняя6,5 | — | 2,4 % | 5 дек. 2018 г. |
27Наблюдать | CVE-2024-47880Эксплойта нет | OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportRowsCommandopenrefine · openrefine · CWE-79 | Средняя6,9 | — | 0,4 % | 24 окт. 2024 г. |
26Наблюдать | CVE-2022-41401Proof of concept | OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, poopenrefine · openrefine · CWE-918 | Средняя6,5 | — | 1,4 % | 4 авг. 2023 г. |
24Наблюдать | CVE-2024-47882Эксплойта нет | OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious projectopenrefine · openrefine · CWE-79 | Средняя6,1 | — | 0,5 % | 24 окт. 2024 г. |
24Наблюдать | CVE-2024-47878Эксплойта нет | Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)openrefine · openrefine · CWE-79 | Средняя6,1 | — | 0,5 % | 24 окт. 2024 г. |
21Наблюдать | CVE-2024-49760Эксплойта нет | OpenRefine has a path traversal in LoadLanguageCommandopenrefine · openrefine · CWE-22 | Средняя5,3 | — | 0,6 % | 24 окт. 2024 г. |
- CVE-2023-4188752В плане
Remote Code exec in project import with mysql jdbc url attack
КритическаяCVSS 9,8Эксплойта нетEPSS 43 %openrefine · openrefine15 сент. 2023 г.
- CVE-2024-4788336Наблюдать
Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %openrefine · butterfly24 окт. 2024 г.
- CVE-2024-4788135Наблюдать
OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %openrefine · openrefine24 окт. 2024 г.
- CVE-2024-4787935Наблюдать
OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %openrefine · openrefine24 окт. 2024 г.
- CVE-2019-358031Наблюдать
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openrefine · openrefine2 янв. 2019 г.
- CVE-2018-2015731Наблюдать
The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing at
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openrefine · openrefine14 дек. 2018 г.
- CVE-2023-3747631Наблюдать
Zip slip in OpenRefine
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %openrefine · openrefine17 июл. 2023 г.
- CVE-2024-2383330Наблюдать
OpenRefine JDBC Attack Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openrefine · openrefine12 февр. 2024 г.
- CVE-2023-4188630Наблюдать
OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openrefine · openrefine15 сент. 2023 г.
- CVE-2018-1985927Наблюдать
OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.
СредняяCVSS 6,5Proof of conceptEPSS 2 %openrefine · openrefine5 дек. 2018 г.
- CVE-2024-4788027Наблюдать
OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportRowsCommand
СредняяCVSS 6,9Эксплойта нетEPSS 0 %openrefine · openrefine24 окт. 2024 г.
- CVE-2022-4140126Наблюдать
OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, po
СредняяCVSS 6,5Proof of conceptEPSS 1 %openrefine · openrefine4 авг. 2023 г.
- CVE-2024-4788224Наблюдать
OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openrefine · openrefine24 окт. 2024 г.
- CVE-2024-4787824Наблюдать
Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %openrefine · openrefine24 окт. 2024 г.
- CVE-2024-4976021Наблюдать
OpenRefine has a path traversal in LoadLanguageCommand
СредняяCVSS 5,3Эксплойта нетEPSS 1 %openrefine · openrefine24 окт. 2024 г.