dataease kayıtları
dataease üreticisine ait 72 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 12
- Düzeltme kaydı olan
- %61,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')18
- CWE-502 Deserialization of Untrusted Data8
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-153 Improper Neutralization of Substitution Characters4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
72 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
50Planlayın | CVE-2024-56511Kavram kanıtı | DataEase has an unauthorized vulnerabilitydataease · dataease · CWE-289 | Kritik9,3 | — | %44,5 | 10 Oca 2025 |
47Planlayın | CVE-2025-49002Kavram kanıtı | Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerabilitydataease · dataease · CWE-290 | Yüksek8,2 | — | %50,3 | 3 Haz 2025 |
39İzleyin | CVE-2022-39312İstismar yok | Dataease Mysql Data Source JDBC Connection Parameters Not Verified Leads to Deserialization Vulnerabilitydataease · dataease · CWE-20 | Kritik9,8 | — | %1,6 | 25 Eki 2022 |
39İzleyin | CVE-2024-46997İstismar yok | DataEase's H2 datasource has a remote command execution riskdataease · dataease · CWE-74 | Kritik9,8 | — | %1,4 | 23 Eyl 2024 |
39İzleyin | CVE-2023-33963İstismar yok | DataEase data source has deserialization vulnerabilitydataease · dataease · CWE-502 | Kritik9,8 | — | %1,3 | 1 Haz 2023 |
39İzleyin | CVE-2022-34113İstismar yok | An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.dataease · dataease | Kritik9,8 | — | %1,3 | 22 Tem 2022 |
39İzleyin | CVE-2022-34115İstismar yok | DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.dataease · dataease · CWE-434 | Kritik9,8 | — | %1,2 | 22 Tem 2022 |
39İzleyin | CVE-2023-37258İstismar yok | DataEase has a SQL injection vulnerability that can bypass blacklistsdataease · dataease · CWE-89 | Kritik9,8 | — | %1,1 | 25 Tem 2023 |
39İzleyin | CVE-2023-28437İstismar yok | SQL injection vulnerability due to the keyword blacklist for defending against SQL injection will be bypasseddataease · dataease · CWE-89 | Kritik9,8 | — | %0,9 | 24 Mar 2023 |
39İzleyin | CVE-2024-57707İstismar yok | An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.dataease · dataease · CWE-94 | Kritik9,8 | — | %0,8 | 7 Şub 2025 |
37İzleyin | CVE-2024-47073Kavram kanıtı | Dataease arbitrary interface access vulnerabilitydataease · dataease · CWE-347 | Kritik9,3 | — | %1,3 | 7 Kas 2024 |
37İzleyin | CVE-2026-32140İstismar yok | Dataease: Redshift JDBC RCE Bypassdataease · dataease · CWE-22 | Kritik9,3 | — | %0,9 | 12 Mar 2026 |
37İzleyin | CVE-2024-52295İstismar yok | DataEase has a forged JWT token vulnerabilitydataease · dataease · CWE-798 | Kritik9,3 | — | %0,9 | 13 Kas 2024 |
37İzleyin | CVE-2024-47074İstismar yok | Dataease PostgreSQL Data Source JDBC Connection Parameters Not Verified Leads to Deserialization Vulnerabilitydataease · dataease · CWE-502 | Kritik9,3 | — | %0,6 | 11 Eki 2024 |
37İzleyin | CVE-2026-32137İstismar yok | DataEase SQL Injection Vulnerabilitydataease · dataease · CWE-89 | Kritik9,3 | — | %0,6 | 12 Mar 2026 |
36İzleyin | CVE-2025-49001Kavram kanıtı | Dataease Authentication Bypass Vulnerabilitydataease · dataease · CWE-287 | Yüksek7,7 | — | %21,1 | 3 Haz 2025 |
36İzleyin | CVE-2024-23328İstismar yok | The Dataease datasource exists deserialization and arbitrary file read vulnerabilitydataease · dataease · CWE-502 | Kritik9,1 | — | %1,2 | 28 Şub 2024 |
35İzleyin | CVE-2025-57772İstismar yok | Dataease H2 JDBC RCE Bypassdataease · dataease · CWE-94 | Yüksek8,2 | — | %9,3 | 25 Ağu 2025 |
35İzleyin | CVE-2023-28637İstismar yok | DataEase AWS redshift data source exists for remote code execution vulnerabilitydataease · dataease · CWE-74 | Yüksek8,8 | — | %1,3 | 28 Mar 2023 |
35İzleyin | CVE-2022-23331İstismar yok | In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.dataease · dataease | Yüksek8,8 | — | %1,2 | 8 Şub 2022 |
35İzleyin | CVE-2025-64163İstismar yok | DataEase's DB2 is vulnerable to SSRFdataease · dataease · CWE-918 | Yüksek8,9 | — | %1,1 | 5 Kas 2025 |
35İzleyin | CVE-2025-49003İstismar yok | Dataease H2 JDBC Connection Remote Code Executiondataease · dataease · CWE-153 | Yüksek8,9 | — | %0,9 | 26 Haz 2025 |
35İzleyin | CVE-2022-34114İstismar yok | Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.dataease · dataease · CWE-89 | Yüksek8,8 | — | %0,9 | 22 Tem 2022 |
35İzleyin | CVE-2025-53006İstismar yok | Dataease PostgreSQL & Redshift Data Source JDBC Connection Parameters Bypass Vulnerabilitydataease · dataease · CWE-153 | Yüksek8,9 | — | %0,6 | 2 Tem 2025 |
35İzleyin | CVE-2025-64164İstismar yok | DataEase is vulnerable to Oracle JNDI Injectiondataease · dataease · CWE-502 | Yüksek8,9 | — | %0,6 | 5 Kas 2025 |
- CVE-2024-5651150Planlayın
DataEase has an unauthorized vulnerability
KritikCVSS 9,3Kavram kanıtıEPSS %44dataease · dataease10 Oca 2025
- CVE-2025-4900247Planlayın
Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerability
YüksekCVSS 8,2Kavram kanıtıEPSS %50dataease · dataease3 Haz 2025
- CVE-2022-3931239İzleyin
Dataease Mysql Data Source JDBC Connection Parameters Not Verified Leads to Deserialization Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2dataease · dataease25 Eki 2022
- CVE-2024-4699739İzleyin
DataEase's H2 datasource has a remote command execution risk
KritikCVSS 9,8İstismar yokEPSS %1dataease · dataease23 Eyl 2024
- CVE-2023-3396339İzleyin
DataEase data source has deserialization vulnerability
KritikCVSS 9,8İstismar yokEPSS %1dataease · dataease1 Haz 2023
- CVE-2022-3411339İzleyin
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
KritikCVSS 9,8İstismar yokEPSS %1dataease · dataease22 Tem 2022
- CVE-2022-3411539İzleyin
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
KritikCVSS 9,8İstismar yokEPSS %1dataease · dataease22 Tem 2022
- CVE-2023-3725839İzleyin
DataEase has a SQL injection vulnerability that can bypass blacklists
KritikCVSS 9,8İstismar yokEPSS %1dataease · dataease25 Tem 2023
- CVE-2023-2843739İzleyin
SQL injection vulnerability due to the keyword blacklist for defending against SQL injection will be bypassed
KritikCVSS 9,8İstismar yokEPSS %1dataease · dataease24 Mar 2023
- CVE-2024-5770739İzleyin
An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.
KritikCVSS 9,8İstismar yokEPSS %1dataease · dataease7 Şub 2025
- CVE-2024-4707337İzleyin
Dataease arbitrary interface access vulnerability
KritikCVSS 9,3Kavram kanıtıEPSS %1dataease · dataease7 Kas 2024
- CVE-2026-3214037İzleyin
Dataease: Redshift JDBC RCE Bypass
KritikCVSS 9,3İstismar yokEPSS %1dataease · dataease12 Mar 2026
- CVE-2024-5229537İzleyin
DataEase has a forged JWT token vulnerability
KritikCVSS 9,3İstismar yokEPSS %1dataease · dataease13 Kas 2024
- CVE-2024-4707437İzleyin
Dataease PostgreSQL Data Source JDBC Connection Parameters Not Verified Leads to Deserialization Vulnerability
KritikCVSS 9,3İstismar yokEPSS %1dataease · dataease11 Eki 2024
- CVE-2026-3213737İzleyin
DataEase SQL Injection Vulnerability
KritikCVSS 9,3İstismar yokEPSS %1dataease · dataease12 Mar 2026
- CVE-2025-4900136İzleyin
Dataease Authentication Bypass Vulnerability
YüksekCVSS 7,7Kavram kanıtıEPSS %21dataease · dataease3 Haz 2025
- CVE-2024-2332836İzleyin
The Dataease datasource exists deserialization and arbitrary file read vulnerability
KritikCVSS 9,1İstismar yokEPSS %1dataease · dataease28 Şub 2024
- CVE-2025-5777235İzleyin
Dataease H2 JDBC RCE Bypass
YüksekCVSS 8,2İstismar yokEPSS %9dataease · dataease25 Ağu 2025
- CVE-2023-2863735İzleyin
DataEase AWS redshift data source exists for remote code execution vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1dataease · dataease28 Mar 2023
- CVE-2022-2333135İzleyin
In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.
YüksekCVSS 8,8İstismar yokEPSS %1dataease · dataease8 Şub 2022
- CVE-2025-6416335İzleyin
DataEase's DB2 is vulnerable to SSRF
YüksekCVSS 8,9İstismar yokEPSS %1dataease · dataease5 Kas 2025
- CVE-2025-4900335İzleyin
Dataease H2 JDBC Connection Remote Code Execution
YüksekCVSS 8,9İstismar yokEPSS %1dataease · dataease26 Haz 2025
- CVE-2022-3411435İzleyin
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
YüksekCVSS 8,8İstismar yokEPSS %1dataease · dataease22 Tem 2022
- CVE-2025-5300635İzleyin
Dataease PostgreSQL & Redshift Data Source JDBC Connection Parameters Bypass Vulnerability
YüksekCVSS 8,9İstismar yokEPSS %1dataease · dataease2 Tem 2025
- CVE-2025-6416435İzleyin
DataEase is vulnerable to Oracle JNDI Injection
YüksekCVSS 8,9İstismar yokEPSS %1dataease · dataease5 Kas 2025