Vulnerabilities (CVE)

Filtered by vendor Dataease Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-34113 1 Dataease 1 Dataease 2023-08-08 N/A 9.8 CRITICAL
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
CVE-2023-37258 1 Dataease 1 Dataease 2023-08-01 N/A 9.8 CRITICAL
DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulnerability that can bypass blacklists. The vulnerability has been fixed in v1.18.9. There are no known workarounds.