CVE Tools

Dataease

96 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Dataease, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Dataease CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Dataease CVEs per month
MonthCVEs
2024-101
2024-112
2024-122
2025-011
2025-021
2025-033
2025-041
2025-051
2025-066
2025-072
2025-082
2025-093
2025-104
2025-113
2025-120
2026-011
2026-020
2026-034
2026-049
2026-051
2026-060
2026-0720
2026-083
2026-091

Severity

How the 96 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical3243%
  • High2837%
  • Medium1520%

Latest CVEs

The 15 most recently published vulnerabilities affecting Dataease.

  1. CVE-2023-40772A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.4.3
  2. CVE-2026-82879DataEase before 2.10.26 Access Control Bypass via Share Tickets6.3
  3. CVE-2026-82878DataEase before 2.10.26 Missing Object-Level Authorization on Geographic, Linkage and Chart Endpoints6.3
  4. CVE-2026-45532DataEase has a Path Traversal Vulnerability—
  5. CVE-2026-49867DataEase: Authenticated Stored XSS in DataEase Template Static Resources—
  6. CVE-2026-46684DataEase: Unauthorized Command Execution Vulnerability—
  7. CVE-2026-45320DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection—
  8. CVE-2026-45535DataEase: Stored SQL Injection Vulnerability—
  9. CVE-2026-45533DataEase: Path Traversal Vulnerability—
  10. CVE-2026-50124DataEase: Remote Code Execution (RCE) via Zip Protocol & File Dropper—
  11. CVE-2026-50030DataEase: Arbitrary SQL execution in preview path (direct data disclosure)—
  12. CVE-2026-45419DataEase: Arbitrary File Write Vulnerability—
  13. CVE-2026-45417DataEase: SQL injection vulnerability—
  14. CVE-2026-45534DataEase: RCE Vulnerability—
  15. CVE-2026-50530DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshared Datasets—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store