OpenRefine kayıtları
openrefine üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %86,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-36 Absolute Path Traversal1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2023-41887İstismar yok | Remote Code exec in project import with mysql jdbc url attackopenrefine · openrefine · CWE-89 | Kritik9,8 | — | %42,5 | 15 Eyl 2023 |
36İzleyin | CVE-2024-47883İstismar yok | Butterfly has path/URL confusion in resource handling leading to multiple weaknessesopenrefine · butterfly · CWE-36 | Kritik9,1 | — | %1,6 | 24 Eki 2024 |
35İzleyin | CVE-2024-47881İstismar yok | OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)openrefine · openrefine · CWE-89 | Yüksek8,8 | — | %0,7 | 24 Eki 2024 |
35İzleyin | CVE-2024-47879İstismar yok | OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)openrefine · openrefine · CWE-94 | Yüksek8,8 | — | %0,4 | 24 Eki 2024 |
31İzleyin | CVE-2019-3580İstismar yok | OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.openrefine · openrefine · CWE-22 | Yüksek7,5 | — | %1,9 | 2 Oca 2019 |
31İzleyin | CVE-2018-20157İstismar yok | The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing atopenrefine · openrefine · CWE-611 | Yüksek7,5 | — | %1,7 | 14 Ara 2018 |
31İzleyin | CVE-2023-37476İstismar yok | Zip slip in OpenRefineopenrefine · openrefine · CWE-22 | Yüksek7,8 | — | %0,6 | 17 Tem 2023 |
30İzleyin | CVE-2024-23833İstismar yok | OpenRefine JDBC Attack Vulnerabilityopenrefine · openrefine · CWE-22 | Yüksek7,5 | — | %1,0 | 12 Şub 2024 |
30İzleyin | CVE-2023-41886İstismar yok | OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attackopenrefine · openrefine · CWE-89 | Yüksek7,5 | — | %1,0 | 15 Eyl 2023 |
27İzleyin | CVE-2018-19859Kavram kanıtı | OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.openrefine · openrefine · CWE-22 | Orta6,5 | — | %2,4 | 5 Ara 2018 |
27İzleyin | CVE-2024-47880İstismar yok | OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportRowsCommandopenrefine · openrefine · CWE-79 | Orta6,9 | — | %0,4 | 24 Eki 2024 |
26İzleyin | CVE-2022-41401Kavram kanıtı | OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, poopenrefine · openrefine · CWE-918 | Orta6,5 | — | %1,4 | 4 Ağu 2023 |
24İzleyin | CVE-2024-47882İstismar yok | OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious projectopenrefine · openrefine · CWE-79 | Orta6,1 | — | %0,5 | 24 Eki 2024 |
24İzleyin | CVE-2024-47878İstismar yok | Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)openrefine · openrefine · CWE-79 | Orta6,1 | — | %0,4 | 24 Eki 2024 |
21İzleyin | CVE-2024-49760İstismar yok | OpenRefine has a path traversal in LoadLanguageCommandopenrefine · openrefine · CWE-22 | Orta5,3 | — | %0,6 | 24 Eki 2024 |
- CVE-2023-4188752Planlayın
Remote Code exec in project import with mysql jdbc url attack
KritikCVSS 9,8İstismar yokEPSS %43openrefine · openrefine15 Eyl 2023
- CVE-2024-4788336İzleyin
Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
KritikCVSS 9,1İstismar yokEPSS %2openrefine · butterfly24 Eki 2024
- CVE-2024-4788135İzleyin
OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
YüksekCVSS 8,8İstismar yokEPSS %1openrefine · openrefine24 Eki 2024
- CVE-2024-4787935İzleyin
OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0openrefine · openrefine24 Eki 2024
- CVE-2019-358031İzleyin
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
YüksekCVSS 7,5İstismar yokEPSS %2openrefine · openrefine2 Oca 2019
- CVE-2018-2015731İzleyin
The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing at
YüksekCVSS 7,5İstismar yokEPSS %2openrefine · openrefine14 Ara 2018
- CVE-2023-3747631İzleyin
Zip slip in OpenRefine
YüksekCVSS 7,8İstismar yokEPSS %1openrefine · openrefine17 Tem 2023
- CVE-2024-2383330İzleyin
OpenRefine JDBC Attack Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1openrefine · openrefine12 Şub 2024
- CVE-2023-4188630İzleyin
OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack
YüksekCVSS 7,5İstismar yokEPSS %1openrefine · openrefine15 Eyl 2023
- CVE-2018-1985927İzleyin
OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.
OrtaCVSS 6,5Kavram kanıtıEPSS %2openrefine · openrefine5 Ara 2018
- CVE-2024-4788027İzleyin
OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportRowsCommand
OrtaCVSS 6,9İstismar yokEPSS %0openrefine · openrefine24 Eki 2024
- CVE-2022-4140126İzleyin
OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, po
OrtaCVSS 6,5Kavram kanıtıEPSS %1openrefine · openrefine4 Ağu 2023
- CVE-2024-4788224İzleyin
OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project
OrtaCVSS 6,1İstismar yokEPSS %0openrefine · openrefine24 Eki 2024
- CVE-2024-4787824İzleyin
Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)
OrtaCVSS 6,1İstismar yokEPSS %0openrefine · openrefine24 Eki 2024
- CVE-2024-4976021İzleyin
OpenRefine has a path traversal in LoadLanguageCommand
OrtaCVSS 5,3İstismar yokEPSS %1openrefine · openrefine24 Eki 2024