Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 1.1% | — | DataeaseAI | 14/9/2026 | 22/9/2026 | A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component. | |
| Aplazada | Media (5.1) | 0.35% | — | DataeaseAI | 13/9/2026 | 15/9/2026 | A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument… | |
| Aplazada | Media (5.3) | 0.36% | — | DataeaseAI | 31/8/2026 | 8/9/2026 | DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid ticket issued for one share can be reused against another (ShareTicketManage.validateTicket / POST /de2api/share/proxyInfo). The POST /de2api/share/validate endpoint… | |
| Aplazada | Media (5.3) | 0.34% | — | DataeaseAI | 31/8/2026 | 8/9/2026 | DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart… | |
| Aplazada | Alta (8.7) | 0.52% | — | DataeaseAI | 18/8/2026 | 18/9/2026 | DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during string truncation. The vulnerability has been fixed in v2.10.23. No… | |
| Aplazada | Alta (7.1) | 0.56% | — | DataeaseAI | 15/7/2026 | 17/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/upload, creating an H2 datasource that uses the zip: protocol, and executing an SQL dataset path where CalciteProvider.jdbcFetchResultField… | |
| Aplazada | Alta (7.1) | 0.47% | — | DataeaseAI | 15/7/2026 | 18/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlCheck through /de2api/datasetData/previewSql, accepts PreviewSqlDTO.sql, PreviewSqlDTO.datasourceId, and PreviewSqlDTO.isCross, then DatasetDataManage.previewSql stores… | |
| Aplazada | Media (6.3) | 0.47% | — | DataeaseAI | 15/7/2026 | 18/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources let authenticated users submit TemplateManageRequest.staticResource through POST /de2api/templateManage/save or DataVisualizationServer.decompression, after which StaticResourceServer.saveFilesToServe… | |
| Aplazada | Crítica (9.5) | 0.32% | — | DataeaseAI | 15/7/2026 | 17/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), which checks only token presence and length before userBOByToken(token) uses JWT.decode() without signature verification,… | |
| Aplazada | Alta (8.7) | 0.38% | — | DataeaseAI | 15/7/2026 | 16/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL variable defaultValue entries such as ${var} and SqlparserUtils.handleVariableDefaultValue() inserts them with String.replace() without escaping or parameterization, causing… | |
| Aplazada | Crítica (9) | 0.64% | — | DataeaseAIAmazon Redshift DriverAISpringframework Spring FrameworkAI | 15/7/2026 | 16/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.springframework.context.support.FileSystemXmlApplicationContext so… | |
| Aplazada | Alta (8.3) | 0.46% | — | DataeaseAI | 15/7/2026 | 17/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequences such as ../ in the bulk delete API endpoint and pass attacker-controlled identifiers to ExportCenterManage.delete, allowing recursive deletion of arbitrary server… | |
| Aplazada | Alta (8.5) | 0.46% | — | DataeaseAI | 15/7/2026 | 18/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesToServe, and the /de2api/templateManage/save endpoint with attacker-controlled staticResource names and Base64 content, allowing path traversal and… | |
| Aplazada | Alta (8.7) | 0.38% | — | DataeaseAI | 15/7/2026 | 16/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configuration.getSchema() into getTablesSql and execute the resulting SQL with executeQuery in io.dataease.datasource.provider.CalciteProvider#checkStatus, allowing SQL injection… | |
| Aplazada | Alta (8.7) | 0.47% | — | DataeaseAI | 15/7/2026 | 17/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such as ${deptId} are processed by SqlparserUtils.transFilter(), whose final branch returns raw user input for non-in and non-between operators before SubstitutedSql.replace("${var}", value) splices it… | |
| Aplazada | Alta (8.3) | 0.45% | — | DataeaseAI | 7/7/2026 | 8/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who can obtain a passwordless share for a resource and user to use the known key link-pwd-fit2cloud to forge linkToken JWTs, bypass TokenFilter… | |
| Aplazada | Media (5.1) | 0.47% | — | DataeaseAI | 7/7/2026 | 8/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stored component content with Vue v-html without server-side HTML sanitization, allowing an authenticated user who can edit dashboard component data to inject HTML with executable event handlers that… | |
| Aplazada | Alta (8.7) | 0.41% | — | DataeaseAI | 7/7/2026 | 9/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter values directly into generated SQL in Quota2SQLObj.getYWheres() without applying the SQL literal validation and escaping used by other filter paths, allowing an… | |
| Aplazada | Alta (8.7) | 0.80% | — | DataeaseAI | 7/7/2026 | 8/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows an authenticated attacker to upload a zip archive disguised with a .ttf extension through FontManage.saveFile and then exploit it through the zip protocol to achieve remote… | |
| Aplazada | Alta (7.2) | 0.46% | — | DataeaseAI | 7/7/2026 | 8/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows authenticated users to submit an arbitrary fileTransName when creating a font record; when the record is later deleted, the backend concatenates that stored value with the font storage directory and… | |
| Aplazada | Alta (8.7) | 0.60% | — | DataeaseAIH2AI | 7/7/2026 | 8/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation logic can be bypassed with special Unicode characters whose case-conversion behavior differs between DataEase validation and H2 parsing, allowing attackers to smuggle dangerous parameters such as init… | |
| Aplazada | Alta (8.7) | 0.36% | — | DataeaseAI | 7/7/2026 | 9/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @DePermit permission validation annotation, allowing any authenticated user to specify datasourceId=-1, access the built-in engine database, execute arbitrary SQL… | |
| Aplazada | Alta (8.7) | 0.64% | — | DataeaseAI | 7/7/2026 | 8/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (/exportCenter/download/{id}), delete (/exportCenter/delete), retry (/exportCenter/retry/{id}), or generate download links (/exportCenter/generateDownloadUri/{id}) for export tasks belonging to other… | |
| Aplazada | Alta (7.1) | 0.41% | — | DataeaseAI | 7/7/2026 | 8/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the resourceId in the link token and fails to validate whether tableId and field IDs in the request body belong to the shared resource, allowing an attacker with a… | |
| Aplazada | Alta (8.7) | 0.50% | — | DataeaseAI | 7/7/2026 | 8/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validating the share password or ticket, allowing unauthenticated attackers who know a protected share UUID to obtain a valid link token for… |