7.5

CVSS4.0

CVE-2026-40901 - DataEase: Quartz Deserialization โ†’ Remote Code Execution

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer deserialization gadget chain. Quartz 2.3.2, also bundled in the application, deserializesโ€ฆ

๐Ÿ“… Published: April 16, 2026, 8:57 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:30 a.m.

8.7

CVSS4.0

CVE-2026-40900 - DataEase has SQL Injection via Stacked Queries

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api/datasetData/previewSql endpoint. The user-supplied SQL is wrapped in a subquery without validation that the input is a single SELECT statement. Combiโ€ฆ

๐Ÿ“… Published: April 16, 2026, 8:53 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 11 p.m.

8.3

CVSS4.0

CVE-2026-40899 - DataEase has an Arbitrary File Read Vulnerability

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mysql class uses Lombok's @Data annotation, which auto-generates a public setter for the illegalParametโ€ฆ

๐Ÿ“… Published: April 16, 2026, 7:48 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:43 a.m.

8.6

CVSS4.0

CVE-2026-33207 - DataEase SQL Injection Vulnerability

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /datasource/getTableField endpoint. The getTableFiledSql method in CalciteProvider.java incorporates the tableName parameter directly into SQL query strings โ€ฆ

๐Ÿ“… Published: April 16, 2026, 7:37 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9 p.m.

8.6

CVSS4.0

CVE-2026-33122 - DataEase has SQL Injection via Datasource Management

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource update process. When a new table definition is added during a datasource update via /de2api/datasource/update, the deTableName field from the โ€ฆ

๐Ÿ“… Published: April 16, 2026, 7:24 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 10 p.m.

7.1

CVSS4.0

CVE-2025-54502 - AMD APCB SMM Driver Privilege Escalation via Incorrect Boot Service Use

Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.

๐Ÿ“… Published: April 16, 2026, 6:46 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:30 a.m.

5.9

CVSS4.0

CVE-2025-54510 -

A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity.

๐Ÿ“… Published: April 16, 2026, 6:44 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:30 a.m.

8.3

CVSS3.1

CVE-2026-6442 - Improper Command Detection Logic Allows RCE in Cortex Code Command-Line Interface

Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could exploit this by embedding specially crafted commands in untrusted content, such as a malicious repository, causing the CLI agent tโ€ฆ

๐Ÿ“… Published: April 16, 2026, 6:43 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:30 a.m.

5.6

CVSS4.0

CVE-2023-20585 - Insufficient RMP Checks in IOMMU Allow Host Buffer Outโ€‘ofโ€‘Bounds Access

Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in a potential loss of confidential guest integrity.

๐Ÿ“… Published: April 16, 2026, 6:42 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3 a.m.

8.7

CVSS4.0

CVE-2026-33121 - DataEase has SQL Injection via Datasource Save Flow

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource saving process. The deTableName field from the Base64-encoded datasource configuration is used to construct a DDL statement via simple string โ€ฆ

๐Ÿ“… Published: April 16, 2026, 6:16 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:30 a.m.
Total resulsts: 345165
Page 26 of 34,517
ยซ previous page ยป next page
Filters