Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-58441 Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerabil… Knowage 8.1.37+ Fix from $1,6002026-01-07 CRITICAL 9.8 CVE-2025-59954 Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using a… Knowage 8.1.27+ Fix from $2,3002025-09-30 MEDIUM 5.3 CVE-2025-55007 Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, Knowage is vulnerable to server-side request forgery. T… Knowage 8.1.37+ Fix from $1,6002025-09-01 CRITICAL 9.1 CVE-2024-54794EPSS 13% The script input feature of SpagoBI 3.5.1 allows arbitrary code execution. Spagobi No fix yet Fix from $2,3002025-01-21 MEDIUM 6.1 CVE-2024-54792 A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead a… Spagobi No fix yet Fix from $1,6002025-01-21 MEDIUM 5.4 CVE-2024-54795 SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function. Spagobi No fix yet Fix from $1,6002025-01-21 HIGH 8.8 CVE-2023-38702 Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8.1.8, the endpoint `/knowage/… Knowage 8.1.8+ Fix from $1,9502023-08-04 MEDIUM 6.5 CVE-2023-37472 Knowage is an open source suite for business analytics. The application often use user supplied data to create HQL queries without prior sanitization… Knowage 8.1.8+ Fix from $1,6002023-07-14 MEDIUM 6.5 CVE-2023-36819 Knowage is the professional open source suite for modern business analytics over traditional sources and big data systems. The endpoint `_/knowage/re… Knowage 8.1.8+ Fix from $1,6002023-07-03 MEDIUM 6.5 CVE-2023-35154 Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register a… Knowage 8.1.8+ Fix from $1,6002023-06-23 MEDIUM 6.1 CVE-2022-39295 Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x b… Knowage 7.4.22 / 8.0.9+ Fix from $1,6002022-10-13 MEDIUM 6.1 CVE-2021-30213 Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/Ada… Knowage No fix yet Fix from $1,6002021-05-12 MEDIUM 5.4 CVE-2021-30211 Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signu… Knowage Mitigation only Fix from $1,6002021-05-12 MEDIUM 5.4 CVE-2021-30212 Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/docum… Knowage No fix yet Fix from $1,6002021-05-12 MEDIUM 5.4 CVE-2021-30214EPSS 24% Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter. Knowage No fix yet Fix from $1,6002021-05-12 HIGH 8.8 CVE-2021-30055 A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' paramete… Knowage 7.4+ Fix from $1,9502021-04-05 MEDIUM 6.1 CVE-2021-30058 Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/… Knowage 7.4+ Fix from $1,6002021-04-05 MEDIUM 5.4 CVE-2021-30056 Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publ… Knowage 7.4+ Fix from $1,6002021-04-05 HIGH 8.8 CVE-2013-6231EPSS 10% SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script Spagobi 4.1+ Fix from $1,9502020-01-10 HIGH 8.0 CVE-2013-6234EPSS 7% Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by… Spagobi 4.1+ Fix from $1,9502019-11-22 CRITICAL 9.8 CVE-2019-13188 In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application. Knowage 6.4+ Fix from $2,3002019-09-05 MEDIUM 5.3 CVE-2019-13190 In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page. Knowage after 6.1.1 Fix from $1,6002019-09-05 HIGH 8.8 CVE-2019-13348 In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which… Knowage 6.4+ Fix from $1,9502019-08-28 MEDIUM 6.1 CVE-2019-13189 In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page. Knowage 6.4+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2018-12355 Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue. Knowage Mitigation only Fix from $1,6002018-06-13 MEDIUM 6.8 CVE-2014-7296 The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated user… Spagobi Mitigation only Fix from $1,6002014-10-08