Vulnerability index

Browse CVEs

72 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2023-32310 DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulner… Dataease 1.18.7+ Fix from $1,9502023-06-01 HIGH 8.8 CVE-2023-28637 DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected … Dataease 1.18.5+ Fix from $1,9502023-03-28 CRITICAL 9.8 CVE-2023-28437 Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability ha… Dataease 1.18.5+ Fix from $2,3002023-03-25 MEDIUM 6.1 CVE-2023-28435 Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not lo… Dataease 1.18.5+ Fix from $1,6002023-03-24 MEDIUM 5.4 CVE-2023-25807 DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and stor… Dataease 1.18.3+ Fix from $1,6002023-02-28 HIGH 7.5 CVE-2021-38239 SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/… Dataease 1.2.0+ Fix from $1,9502023-02-15 CRITICAL 9.8 CVE-2022-39312 Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql dat… Dataease 1.15.2+ Fix from $2,3002022-10-25 CRITICAL 9.8 CVE-2022-34113 An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin. Dataease No fix yet Fix from $2,3002022-07-22 CRITICAL 9.8 CVE-2022-34115 DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId. Dataease Patch available Fix from $2,3002022-07-22 HIGH 8.8 CVE-2022-34114 Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId. Dataease Patch available Fix from $1,9502022-07-22 MEDIUM 6.5 CVE-2022-34112 An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normall… Dataease No fix yet Fix from $1,6002022-07-22 HIGH 8.8 CVE-2022-23331 In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password. Dataease No fix yet Fix from $1,9502022-02-08