Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2024-49760
OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the…
Openrefine
3.8.3+
CRITICAL 9.1
CVE-2024-47883
The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class …
Butterfly
after 1.2.6
MEDIUM 6.1
CVE-2024-47882
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes …
Openrefine
3.8.3+
HIGH 8.8
CVE-2024-47879
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `pre…
Openrefine
3.8.3+
HIGH 8.8
CVE-2024-47881
OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extens…
Openrefine
3.8.3+
MEDIUM 6.9
CVE-2024-47880
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that …
Openrefine
3.8.3+
MEDIUM 6.1
CVE-2024-47878
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `…
Openrefine
3.8.3+
HIGH 7.5
CVE-2024-23833
OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=…
Openrefine
3.7.8+
CRITICAL 9.8
CVE-2023-41887EPSS 45%
OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any…
Openrefine
3.7.5+
HIGH 7.5
CVE-2023-41886
OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file read vulnerability allows any …
Openrefine
3.7.5+
MEDIUM 6.5
CVE-2022-41401
OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially…
Openrefine
after 3.5.2
HIGH 7.8
CVE-2023-37476
OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrar…
Openrefine
after 3.7.3
HIGH 7.5
CVE-2019-3580
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
Openrefine
after 3.1
HIGH 7.5
CVE-2018-20157
The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers t…
Openrefine
after 3.1
MEDIUM 6.5
CVE-2018-19859
OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.
Openrefine
Patch available