İçeriğe atla
Noroxi

eng kayıtları

eng üreticisine ait 29 yayımlanmış kayıt.

Tüm kayıtlar

29 kayıt
  • CVE-2024-54794
    40Planlayın

    The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

    KritikCVSS 9,1İstismar yokEPSS %13

    eng · spagobi21 Oca 2025

  • CVE-2019-13188
    40Planlayın

    In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.

    KritikCVSS 9,8İstismar yokEPSS %2

    eng · knowage5 Eyl 2019

  • CVE-2013-6231
    38İzleyin

    SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script

    YüksekCVSS 8,8Kavram kanıtıEPSS %10

    eng · spagobi10 Oca 2020

  • CVE-2025-59954
    37İzleyin

    Knowage Contains a Remote Code Execution Vulnerability

    KritikCVSS 9,3İstismar yokEPSS %1

    eng · knowage30 Eyl 2025

  • CVE-2021-30055
    35İzleyin

    A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year'

    YüksekCVSS 8,8İstismar yokEPSS %2

    eng · knowage5 Nis 2021

  • CVE-2019-13348
    35İzleyin

    In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in clearte

    YüksekCVSS 8,8İstismar yokEPSS %1

    eng · knowage28 Ağu 2019

  • CVE-2023-38702
    35İzleyin

    Knowage Server vulnerable to path traversal via upload functionality

    YüksekCVSS 8,8İstismar yokEPSS %1

    eng · knowage4 Ağu 2023

  • CVE-2013-6234
    34İzleyin

    Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrar

    YüksekCVSS 8,0Kavram kanıtıEPSS %7

    eng · spagobi22 Kas 2019

  • CVE-2021-30214
    28İzleyin

    Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' paramet

    OrtaCVSS 5,4İstismar yokEPSS %24

    eng · knowage12 May 2021

  • CVE-2014-7296
    28İzleyin

    The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authentic

    OrtaCVSS 6,8İstismar yokEPSS %2

    eng · spagobi8 Eki 2014

  • CVE-2023-36819
    26İzleyin

    Knowage-Server vulnerable to Path traversal in download functionalities

    OrtaCVSS 6,5İstismar yokEPSS %1

    eng · knowage3 Tem 2023

  • CVE-2023-37472
    26İzleyin

    Query injection in Knowage server

    OrtaCVSS 6,5İstismar yokEPSS %1

    eng · knowage14 Tem 2023

  • CVE-2023-35154
    26İzleyin

    Knowage-Server vulnerable to account validation bypass

    OrtaCVSS 6,5İstismar yokEPSS %0

    eng · knowage23 Haz 2023

  • CVE-2021-30213
    25İzleyin

    Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS).

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    eng · knowage12 May 2021

  • CVE-2025-58441
    25İzleyin

    Knowage is vulnerable to blind server-side request forgery (SSRF)

    OrtaCVSS 6,3İstismar yokEPSS %0

    eng · knowage7 Oca 2026

  • CVE-2021-30058
    24İzleyin

    Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS).

    OrtaCVSS 6,1İstismar yokEPSS %1

    eng · knowage5 Nis 2021

  • CVE-2019-13189
    24İzleyin

    In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.

    OrtaCVSS 6,1İstismar yokEPSS %1

    eng · knowage28 Ağu 2019

  • CVE-2018-12355
    24İzleyin

    Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.

    OrtaCVSS 6,1İstismar yokEPSS %1

    eng · knowage13 Haz 2018

  • CVE-2022-39295
    24İzleyin

    Improper Neutralization of Alternate XSS Syntax in Knowage-Server

    OrtaCVSS 6,1İstismar yokEPSS %1

    eng · knowage13 Eki 2022

  • CVE-2024-54792
    24İzleyin

    A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel.

    OrtaCVSS 6,1İstismar yokEPSS %0

    eng · spagobi21 Oca 2025

  • CVE-2019-13190
    21İzleyin

    In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token.

    OrtaCVSS 5,3İstismar yokEPSS %1

    eng · knowage5 Eyl 2019

  • CVE-2021-30056
    21İzleyin

    Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS).

    OrtaCVSS 5,4İstismar yokEPSS %1

    eng · knowage5 Nis 2021

  • CVE-2021-30212
    21İzleyin

    Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).

    OrtaCVSS 5,4İstismar yokEPSS %1

    eng · knowage12 May 2021

  • CVE-2024-54795
    21İzleyin

    SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer functi

    OrtaCVSS 5,4İstismar yokEPSS %1

    eng · spagobi21 Oca 2025

  • CVE-2021-30211
    21İzleyin

    Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).

    OrtaCVSS 5,4İstismar yokEPSS %0

    eng · knowage12 May 2021