Known vulnerabilities in DataEase 1.18.22
Vendor:
DataEase
Software:
DataEase
Version:
1.18.22
Software CPE:
cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
Website:
https://dataease.io/
Total vulnerabilities:
4
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Vulnerabilities by Severity
2.10.26
2.10.25
2.10.24
2.10.23
2.10.22
2.10.21
2.10.20
2.10.19
-
2.10.18
2.10.17
2.10.16
2.10.15
2.10.14
2.10.13
2.10.12
2.10.11
2.10.10
2.10.9
2.10.8
2.10.7
2.10.6
2.10.5
2.10.4
1.18.27
2.10.3
1.18.26
2.10.2
1.18.25
2.10.1
1.18.24
2.10.0
2.9.0
2.8.1
1.18.23
2.8.0
1.18.22
2.7.1
1.18.21
2.7.0
1.18.20
2.6.1
1.18.19
2.6.0
1.18.18
2.5.0
1.18.17
2.4.1
2.4.0
1.18.16
2.3.0
1.18.15
1.18.14
2.2.0
2.1.0
1.18.13
1.18.12
2.0.0
1.18.11
1.18.10
1.18.9
1.18.8
1.18.7
1.18.6
1.18.5
1.18.4
1.18.3
1.18.2
1.18.1
1.18.0
1.17.1
1.17.0
1.16.1
1.16.0
1.15.4
1.15.3
1.15.2
1.15.1
1.15.0
1.14.0
1.13.1
1.13.0
1.12.0
1.11.3
1.11.2
1.11.1
1.11.0
1.10.0
1.9.1
1.9.0
1.8.0
1.7.0
1.6.2
1.6.1
1.6.0
1.5.2
1.5.1
1.5.0
1.4.1
1.4.0
1.3.0
1.2.3
1.2.2
1.2.1
1.2.0
1.1.1
1.1.0
1.0.2
1.0.1
1.0.0
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU102391 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-55953 |
CWE-89 | Medium | 1.18.27 | 07.01.2025 |
SB2025010719 |
||
| #VU102389 - Improper Control of Generation of Code ('Code Injection') CVE-2024-55952 |
CWE-94 | Medium | 1.18.27 | 07.01.2025 |
SB2025010719 |
||
| #VU98727 - Deserialization of Untrusted Data CVE-2024-47074 |
CWE-502 | Medium | 1.18.25 | 16.10.2024 |
SB2024101650 |
||
| #VU85619 - Exposure of sensitive information to an unauthorized actor CVE-2024-21733 |
CWE-200 | Medium | 1.18.24 | 19.01.2024 |
SB2024011929 SB2024020819 SB2024030424 and 9 more |