eng kayıtları
eng üreticisine ait 29 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %17,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-287 Improper Authentication3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-918 Server-Side Request Forgery (SSRF)2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
29 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2024-54794İstismar yok | The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.eng · spagobi · CWE-77 | Kritik9,1 | — | %12,8 | 21 Oca 2025 |
40Planlayın | CVE-2019-13188İstismar yok | In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.eng · knowage · CWE-287 | Kritik9,8 | — | %2,5 | 5 Eyl 2019 |
38İzleyin | CVE-2013-6231Kavram kanıtı | SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP scripteng · spagobi · CWE-269 | Yüksek8,8 | — | %9,9 | 10 Oca 2020 |
37İzleyin | CVE-2025-59954İstismar yok | Knowage Contains a Remote Code Execution Vulnerabilityeng · knowage · CWE-94 | Kritik9,3 | — | %0,5 | 30 Eyl 2025 |
35İzleyin | CVE-2021-30055İstismar yok | A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year'eng · knowage · CWE-89 | Yüksek8,8 | — | %1,6 | 5 Nis 2021 |
35İzleyin | CVE-2019-13348İstismar yok | In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in clearteeng · knowage · CWE-522 | Yüksek8,8 | — | %1,5 | 28 Ağu 2019 |
35İzleyin | CVE-2023-38702İstismar yok | Knowage Server vulnerable to path traversal via upload functionalityeng · knowage · CWE-22 | Yüksek8,8 | — | %1,2 | 4 Ağu 2023 |
34İzleyin | CVE-2013-6234Kavram kanıtı | Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrareng · spagobi · CWE-434 | Yüksek8,0 | — | %6,7 | 22 Kas 2019 |
28İzleyin | CVE-2021-30214İstismar yok | Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameteng · knowage · CWE-74 | Orta5,4 | — | %23,8 | 12 May 2021 |
28İzleyin | CVE-2014-7296İstismar yok | The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticeng · spagobi · CWE-94 | Orta6,8 | — | %1,7 | 8 Eki 2014 |
26İzleyin | CVE-2023-36819İstismar yok | Knowage-Server vulnerable to Path traversal in download functionalitieseng · knowage · CWE-22 | Orta6,5 | — | %0,8 | 3 Tem 2023 |
26İzleyin | CVE-2023-37472İstismar yok | Query injection in Knowage servereng · knowage · CWE-89 | Orta6,5 | — | %0,7 | 14 Tem 2023 |
26İzleyin | CVE-2023-35154İstismar yok | Knowage-Server vulnerable to account validation bypasseng · knowage · CWE-287 | Orta6,5 | — | %0,4 | 23 Haz 2023 |
25İzleyin | CVE-2021-30213Kavram kanıtı | Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS).eng · knowage · CWE-79 | Orta6,1 | — | %2,7 | 12 May 2021 |
25İzleyin | CVE-2025-58441İstismar yok | Knowage is vulnerable to blind server-side request forgery (SSRF)eng · knowage · CWE-918 | Orta6,3 | — | %0,2 | 7 Oca 2026 |
24İzleyin | CVE-2021-30058İstismar yok | Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS).eng · knowage · CWE-79 | Orta6,1 | — | %1,0 | 5 Nis 2021 |
24İzleyin | CVE-2019-13189İstismar yok | In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.eng · knowage · CWE-79 | Orta6,1 | — | %0,9 | 28 Ağu 2019 |
24İzleyin | CVE-2018-12355İstismar yok | Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.eng · knowage · CWE-79 | Orta6,1 | — | %0,8 | 13 Haz 2018 |
24İzleyin | CVE-2022-39295İstismar yok | Improper Neutralization of Alternate XSS Syntax in Knowage-Servereng · knowage · CWE-79 | Orta6,1 | — | %0,6 | 13 Eki 2022 |
24İzleyin | CVE-2024-54792İstismar yok | A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel.eng · spagobi · CWE-352 | Orta6,1 | — | %0,3 | 21 Oca 2025 |
21İzleyin | CVE-2019-13190İstismar yok | In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token.eng · knowage · CWE-287 | Orta5,3 | — | %1,4 | 5 Eyl 2019 |
21İzleyin | CVE-2021-30056İstismar yok | Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS).eng · knowage · CWE-79 | Orta5,4 | — | %0,6 | 5 Nis 2021 |
21İzleyin | CVE-2021-30212İstismar yok | Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).eng · knowage · CWE-79 | Orta5,4 | — | %0,6 | 12 May 2021 |
21İzleyin | CVE-2024-54795İstismar yok | SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer functieng · spagobi · CWE-79 | Orta5,4 | — | %0,5 | 21 Oca 2025 |
21İzleyin | CVE-2021-30211İstismar yok | Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).eng · knowage · CWE-79 | Orta5,4 | — | %0,5 | 12 May 2021 |
- CVE-2024-5479440Planlayın
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
KritikCVSS 9,1İstismar yokEPSS %13eng · spagobi21 Oca 2025
- CVE-2019-1318840Planlayın
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
KritikCVSS 9,8İstismar yokEPSS %2eng · knowage5 Eyl 2019
- CVE-2013-623138İzleyin
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
YüksekCVSS 8,8Kavram kanıtıEPSS %10eng · spagobi10 Oca 2020
- CVE-2025-5995437İzleyin
Knowage Contains a Remote Code Execution Vulnerability
KritikCVSS 9,3İstismar yokEPSS %1eng · knowage30 Eyl 2025
- CVE-2021-3005535İzleyin
A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year'
YüksekCVSS 8,8İstismar yokEPSS %2eng · knowage5 Nis 2021
- CVE-2019-1334835İzleyin
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in clearte
YüksekCVSS 8,8İstismar yokEPSS %1eng · knowage28 Ağu 2019
- CVE-2023-3870235İzleyin
Knowage Server vulnerable to path traversal via upload functionality
YüksekCVSS 8,8İstismar yokEPSS %1eng · knowage4 Ağu 2023
- CVE-2013-623434İzleyin
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrar
YüksekCVSS 8,0Kavram kanıtıEPSS %7eng · spagobi22 Kas 2019
- CVE-2021-3021428İzleyin
Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' paramet
OrtaCVSS 5,4İstismar yokEPSS %24eng · knowage12 May 2021
- CVE-2014-729628İzleyin
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authentic
OrtaCVSS 6,8İstismar yokEPSS %2eng · spagobi8 Eki 2014
- CVE-2023-3681926İzleyin
Knowage-Server vulnerable to Path traversal in download functionalities
OrtaCVSS 6,5İstismar yokEPSS %1eng · knowage3 Tem 2023
- CVE-2023-3747226İzleyin
Query injection in Knowage server
OrtaCVSS 6,5İstismar yokEPSS %1eng · knowage14 Tem 2023
- CVE-2023-3515426İzleyin
Knowage-Server vulnerable to account validation bypass
OrtaCVSS 6,5İstismar yokEPSS %0eng · knowage23 Haz 2023
- CVE-2021-3021325İzleyin
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS).
OrtaCVSS 6,1Kavram kanıtıEPSS %3eng · knowage12 May 2021
- CVE-2025-5844125İzleyin
Knowage is vulnerable to blind server-side request forgery (SSRF)
OrtaCVSS 6,3İstismar yokEPSS %0eng · knowage7 Oca 2026
- CVE-2021-3005824İzleyin
Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS).
OrtaCVSS 6,1İstismar yokEPSS %1eng · knowage5 Nis 2021
- CVE-2019-1318924İzleyin
In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
OrtaCVSS 6,1İstismar yokEPSS %1eng · knowage28 Ağu 2019
- CVE-2018-1235524İzleyin
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.
OrtaCVSS 6,1İstismar yokEPSS %1eng · knowage13 Haz 2018
- CVE-2022-3929524İzleyin
Improper Neutralization of Alternate XSS Syntax in Knowage-Server
OrtaCVSS 6,1İstismar yokEPSS %1eng · knowage13 Eki 2022
- CVE-2024-5479224İzleyin
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel.
OrtaCVSS 6,1İstismar yokEPSS %0eng · spagobi21 Oca 2025
- CVE-2019-1319021İzleyin
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token.
OrtaCVSS 5,3İstismar yokEPSS %1eng · knowage5 Eyl 2019
- CVE-2021-3005621İzleyin
Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS).
OrtaCVSS 5,4İstismar yokEPSS %1eng · knowage5 Nis 2021
- CVE-2021-3021221İzleyin
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).
OrtaCVSS 5,4İstismar yokEPSS %1eng · knowage12 May 2021
- CVE-2024-5479521İzleyin
SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer functi
OrtaCVSS 5,4İstismar yokEPSS %1eng · spagobi21 Oca 2025
- CVE-2021-3021121İzleyin
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS).
OrtaCVSS 5,4İstismar yokEPSS %0eng · knowage12 May 2021