CVE-2023-35843
- EPSS 92.37%
- Veröffentlicht 19.06.2023 18:15:09
- Zuletzt bearbeitet 12.12.2024 01:24:18
NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attack...
CVE-2022-3423
- EPSS 0.96%
- Veröffentlicht 07.10.2022 11:15:10
- Zuletzt bearbeitet 25.02.2026 16:21:29
Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0.
CVE-2022-2339
- EPSS 0.56%
- Veröffentlicht 07.07.2022 04:15:11
- Zuletzt bearbeitet 26.08.2025 18:50:51
With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's contents. This attack can lead to leak of sensitive information.
CVE-2022-2079
- EPSS 0.4%
- Veröffentlicht 14.06.2022 09:15:09
- Zuletzt bearbeitet 26.08.2025 18:50:20
Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7+.
CVE-2022-2064
- EPSS 0.31%
- Veröffentlicht 13.06.2022 12:15:08
- Zuletzt bearbeitet 26.08.2025 18:50:20
Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.
CVE-2022-2063
- EPSS 1.07%
- Veröffentlicht 13.06.2022 12:15:08
- Zuletzt bearbeitet 26.08.2025 18:50:20
Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.
CVE-2022-2062
- EPSS 1.25%
- Veröffentlicht 13.06.2022 12:15:08
- Zuletzt bearbeitet 26.08.2025 18:50:20
Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.
CVE-2022-2022
- EPSS 0.42%
- Veröffentlicht 07.06.2022 20:15:08
- Zuletzt bearbeitet 26.08.2025 18:50:20
Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.
- EPSS 0.28%
- Veröffentlicht 10.01.2022 16:15:10
- Zuletzt bearbeitet 26.08.2025 18:50:20
In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the...
- EPSS 0.43%
- Veröffentlicht 10.01.2022 16:15:10
- Zuletzt bearbeitet 26.08.2025 18:50:20
In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpo...