Vulnerability index

Browse CVEs

72 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dataease HIGH 8.1
CVE-2023-32310

DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulner…

Fix: 1.18.7+
Fix from $1,950 2023-06-01
Dataease HIGH 8.8
CVE-2023-28637

DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected …

Fix: 1.18.5+
Fix from $1,950 2023-03-28
Dataease CRITICAL 9.8
CVE-2023-28437

Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability ha…

Fix: 1.18.5+
Fix from $2,300 2023-03-25
Dataease MEDIUM 6.1
CVE-2023-28435

Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not lo…

Fix: 1.18.5+
Fix from $1,600 2023-03-24
Dataease MEDIUM 5.4
CVE-2023-25807

DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and stor…

Fix: 1.18.3+
Fix from $1,600 2023-02-28
Dataease HIGH 7.5
CVE-2021-38239

SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/…

Fix: 1.2.0+
Fix from $1,950 2023-02-15
Dataease CRITICAL 9.8
CVE-2022-39312

Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql dat…

Fix: 1.15.2+
Fix from $2,300 2022-10-25
Dataease CRITICAL 9.8
CVE-2022-34113

An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.

No fix yet
Fix from $2,300 2022-07-22
Dataease CRITICAL 9.8
CVE-2022-34115

DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.

Patch available
Fix from $2,300 2022-07-22
Dataease HIGH 8.8
CVE-2022-34114

Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.

Patch available
Fix from $1,950 2022-07-22
Dataease MEDIUM 6.5
CVE-2022-34112

An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normall…

No fix yet
Fix from $1,600 2022-07-22
Dataease HIGH 8.8
CVE-2022-23331

In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.

No fix yet
Fix from $1,950 2022-02-08