Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2025-58441
Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerabil…
Knowage
8.1.37+
CRITICAL 9.8
CVE-2025-59954
Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using a…
Knowage
8.1.27+
MEDIUM 5.3
CVE-2025-55007
Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, Knowage is vulnerable to server-side request forgery. T…
Knowage
8.1.37+
CRITICAL 9.1
CVE-2024-54794EPSS 13%
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
Spagobi
No fix yet
MEDIUM 6.1
CVE-2024-54792
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead a…
Spagobi
No fix yet
MEDIUM 5.4
CVE-2024-54795
SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.
Spagobi
No fix yet
HIGH 8.8
CVE-2023-38702
Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8.1.8, the endpoint `/knowage/…
Knowage
8.1.8+
MEDIUM 6.5
CVE-2023-37472
Knowage is an open source suite for business analytics. The application often use user supplied data to create HQL queries without prior sanitization…
Knowage
8.1.8+
MEDIUM 6.5
CVE-2023-36819
Knowage is the professional open source suite for modern business analytics over traditional sources and big data systems. The endpoint `_/knowage/re…
Knowage
8.1.8+
MEDIUM 6.5
CVE-2023-35154
Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register a…
Knowage
8.1.8+
MEDIUM 6.1
CVE-2022-39295
Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x b…
Knowage
7.4.22 / 8.0.9+
MEDIUM 6.1
CVE-2021-30213
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/Ada…
Knowage
No fix yet
MEDIUM 5.4
CVE-2021-30211
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signu…
Knowage
Mitigation only
MEDIUM 5.4
CVE-2021-30212
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/docum…
Knowage
No fix yet
MEDIUM 5.4
CVE-2021-30214EPSS 24%
Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.
Knowage
No fix yet
HIGH 8.8
CVE-2021-30055
A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' paramete…
Knowage
7.4+
MEDIUM 6.1
CVE-2021-30058
Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/…
Knowage
7.4+
MEDIUM 5.4
CVE-2021-30056
Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publ…
Knowage
7.4+
HIGH 8.8
CVE-2013-6231EPSS 10%
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
Spagobi
4.1+
HIGH 8.0
CVE-2013-6234EPSS 7%
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by…
Spagobi
4.1+
CRITICAL 9.8
CVE-2019-13188
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
Knowage
6.4+
MEDIUM 5.3
CVE-2019-13190
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
Knowage
after 6.1.1
HIGH 8.8
CVE-2019-13348
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which…
Knowage
6.4+
MEDIUM 6.1
CVE-2019-13189
In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
Knowage
6.4+
MEDIUM 6.1
CVE-2018-12355
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.
Knowage
Mitigation only
MEDIUM 6.8
CVE-2014-7296
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated user…
Spagobi
Mitigation only