Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Spagobi CRITICAL 9.1
CVE-2024-54794EPSS 13%

The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

No fix yet
Fix from $2,300 2025-01-21
Spagobi MEDIUM 6.1
CVE-2024-54792

A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead a…

No fix yet
Fix from $1,600 2025-01-21
Spagobi MEDIUM 5.4
CVE-2024-54795

SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.

No fix yet
Fix from $1,600 2025-01-21
Knowage MEDIUM 6.1
CVE-2021-30213

Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/Ada…

No fix yet
Fix from $1,600 2021-05-12
Knowage MEDIUM 5.4
CVE-2021-30211

Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signu…

Mitigation only
Fix from $1,600 2021-05-12
Knowage MEDIUM 5.4
CVE-2021-30212

Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/docum…

No fix yet
Fix from $1,600 2021-05-12
Knowage MEDIUM 5.4
CVE-2021-30214EPSS 24%

Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.

No fix yet
Fix from $1,600 2021-05-12
Knowage MEDIUM 6.1
CVE-2018-12355

Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.

Mitigation only
Fix from $1,600 2018-06-13
Spagobi MEDIUM 6.8
CVE-2014-7296

The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated user…

Mitigation only
Fix from $1,600 2014-10-08