CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2026-93660 HIGH

SQLBot through 1.10.1 Improper Access Control via Dashboard Update

CVSS 7.1 EPSS 0.43% Sep 18, 2026
CVE-2026-53557 HIGH

SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Command Execution

CVSS 7.7 EPSS 0.34% Sep 17, 2026
CVE-2026-53555 MEDIUM

Stored XSS via SVG Upload

CVSS 5.1 EPSS 0.48% Sep 17, 2026
CVE-2026-53556 MEDIUM

SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read

CVSS 6.0 EPSS 0.48% Sep 17, 2026
CVE-2026-53554 HIGH

SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import Processing

CVSS 7.3 EPSS 0.41% Sep 17, 2026
CVE-2026-72743 MEDIUM

SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html

CVSS 5.1 EPSS 0.30% Aug 10, 2026
CVE-2026-42463 HIGH

SQLBot: Unauthorized Access Vulnerability

CVSS 8.6 EPSS 0.36% May 13, 2026
CVE-2026-33324 CRITICAL

SQLBot prompt injection allows arbitrary SQL execution and remote code execution

CVSS 9.4 EPSS 0.84% May 5, 2026
CVE-2026-5417 MEDIUM

Dataease SQLbot Elasticsearch es_engine.py get_es_data_by_http server-side request forgery

CVSS 5.1 EPSS 0.38% Apr 2, 2026
CVE-2026-32950 HIGH

SQLBot: RCE via SQL Injection in Excel Upload Endpoint

CVSS 8.6 EPSS 1.01% Mar 20, 2026
CVE-2026-32949 HIGH

SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL

CVSS 8.7 EPSS 0.48% Mar 20, 2026
CVE-2026-32622 HIGH

SQLBot: Remote Code Execution via Terminology Poisoning

CVSS 8.6 EPSS 0.77% Mar 19, 2026
CVE-2025-15598 MEDIUM

Dataease SQLBot JWT Token auth.py validateEmbedded signature verification

CVSS 6.3 EPSS 0.19% Mar 3, 2026
CVE-2025-15597 MEDIUM

Dataease SQLBot API Endpoint assistant.py access control

CVSS 5.3 EPSS 0.56% Mar 2, 2026
CVE-2025-69285 HIGH

SQLBot uploadExcel Endpoint has Unauthenticated Arbitrary File Upload vulnerability

CVSS 7.7 EPSS 0.46% Jan 21, 2026

Showing 1 to 15 CVEs · page 1