İçeriğe atla
Noroxi

OpenRefine kayıtları

openrefine üreticisine ait 15 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%86,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

15 kayıt
  • CVE-2023-41887
    52Planlayın

    Remote Code exec in project import with mysql jdbc url attack

    KritikCVSS 9,8İstismar yokEPSS %43

    openrefine · openrefine15 Eyl 2023

  • CVE-2024-47883
    36İzleyin

    Butterfly has path/URL confusion in resource handling leading to multiple weaknesses

    KritikCVSS 9,1İstismar yokEPSS %2

    openrefine · butterfly24 Eki 2024

  • CVE-2024-47881
    35İzleyin

    OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)

    YüksekCVSS 8,8İstismar yokEPSS %1

    openrefine · openrefine24 Eki 2024

  • CVE-2024-47879
    35İzleyin

    OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    openrefine · openrefine24 Eki 2024

  • CVE-2019-3580
    31İzleyin

    OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.

    YüksekCVSS 7,5İstismar yokEPSS %2

    openrefine · openrefine2 Oca 2019

  • CVE-2018-20157
    31İzleyin

    The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing at

    YüksekCVSS 7,5İstismar yokEPSS %2

    openrefine · openrefine14 Ara 2018

  • CVE-2023-37476
    31İzleyin

    Zip slip in OpenRefine

    YüksekCVSS 7,8İstismar yokEPSS %1

    openrefine · openrefine17 Tem 2023

  • CVE-2024-23833
    30İzleyin

    OpenRefine JDBC Attack Vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %1

    openrefine · openrefine12 Şub 2024

  • CVE-2023-41886
    30İzleyin

    OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack

    YüksekCVSS 7,5İstismar yokEPSS %1

    openrefine · openrefine15 Eyl 2023

  • CVE-2018-19859
    27İzleyin

    OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.

    OrtaCVSS 6,5Kavram kanıtıEPSS %2

    openrefine · openrefine5 Ara 2018

  • CVE-2024-47880
    27İzleyin

    OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportRowsCommand

    OrtaCVSS 6,9İstismar yokEPSS %0

    openrefine · openrefine24 Eki 2024

  • CVE-2022-41401
    26İzleyin

    OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, po

    OrtaCVSS 6,5Kavram kanıtıEPSS %1

    openrefine · openrefine4 Ağu 2023

  • CVE-2024-47882
    24İzleyin

    OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project

    OrtaCVSS 6,1İstismar yokEPSS %0

    openrefine · openrefine24 Eki 2024

  • CVE-2024-47878
    24İzleyin

    Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)

    OrtaCVSS 6,1İstismar yokEPSS %0

    openrefine · openrefine24 Eki 2024

  • CVE-2024-49760
    21İzleyin

    OpenRefine has a path traversal in LoadLanguageCommand

    OrtaCVSS 5,3İstismar yokEPSS %1

    openrefine · openrefine24 Eki 2024