Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openrefine MEDIUM 5.3
CVE-2024-49760

OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the…

Fix: 3.8.3+
Fix from $1,600 2024-10-24
Butterfly CRITICAL 9.1
CVE-2024-47883

The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class …

Fix: after 1.2.6
Fix from $2,300 2024-10-24
Openrefine MEDIUM 6.1
CVE-2024-47882

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes …

Fix: 3.8.3+
Fix from $1,600 2024-10-24
Openrefine HIGH 8.8
CVE-2024-47879

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `pre…

Fix: 3.8.3+
Fix from $1,950 2024-10-24
Openrefine HIGH 8.8
CVE-2024-47881

OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extens…

Fix: 3.8.3+
Fix from $1,950 2024-10-24
Openrefine MEDIUM 6.9
CVE-2024-47880

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that …

Fix: 3.8.3+
Fix from $1,600 2024-10-24
Openrefine MEDIUM 6.1
CVE-2024-47878

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `…

Fix: 3.8.3+
Fix from $1,600 2024-10-24
Openrefine HIGH 7.5
CVE-2024-23833

OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=…

Fix: 3.7.8+
Fix from $1,950 2024-02-12
Openrefine CRITICAL 9.8
CVE-2023-41887EPSS 45%

OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any…

Fix: 3.7.5+
Fix from $2,300 2023-09-15
Openrefine HIGH 7.5
CVE-2023-41886

OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file read vulnerability allows any …

Fix: 3.7.5+
Fix from $1,950 2023-09-15
Openrefine MEDIUM 6.5
CVE-2022-41401

OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially…

Fix: after 3.5.2
Fix from $1,600 2023-08-04
Openrefine HIGH 7.8
CVE-2023-37476

OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrar…

Fix: after 3.7.3
Fix from $1,950 2023-07-17
Openrefine HIGH 7.5
CVE-2019-3580

OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.

Fix: after 3.1
Fix from $1,950 2019-01-03
Openrefine HIGH 7.5
CVE-2018-20157

The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers t…

Fix: after 3.1
Fix from $1,950 2018-12-15
Openrefine MEDIUM 6.5
CVE-2018-19859

OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.

Patch available
Fix from $1,600 2018-12-05