Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2024-54794EPSS 13% The script input feature of SpagoBI 3.5.1 allows arbitrary code execution. Spagobi No fix yet Fix from $2,3002025-01-21 MEDIUM 6.1 CVE-2024-54792 A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead a… Spagobi No fix yet Fix from $1,6002025-01-21 MEDIUM 5.4 CVE-2024-54795 SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function. Spagobi No fix yet Fix from $1,6002025-01-21 MEDIUM 6.1 CVE-2021-30213 Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/Ada… Knowage No fix yet Fix from $1,6002021-05-12 MEDIUM 5.4 CVE-2021-30211 Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signu… Knowage Mitigation only Fix from $1,6002021-05-12 MEDIUM 5.4 CVE-2021-30212 Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/docum… Knowage No fix yet Fix from $1,6002021-05-12 MEDIUM 5.4 CVE-2021-30214EPSS 24% Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter. Knowage No fix yet Fix from $1,6002021-05-12 MEDIUM 6.1 CVE-2018-12355 Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue. Knowage Mitigation only Fix from $1,6002018-06-13 MEDIUM 6.8 CVE-2014-7296 The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated user… Spagobi Mitigation only Fix from $1,6002014-10-08