CVE-2023-40772Medium· 4.3▾ TwilightPoC availableA directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 23.7 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
1.0%
Exploit / PoC code exists
A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90529Low· 3.5A vulnerability has been found in DataEase up to 2.10.25/2.10.26
CVE-2026-53556Medium· 6.0SQLBot is an intelligent Text-to-SQL system based on large language models and RAG
CVE-2026-53555Medium· 5.1SQLBot is an intelligent Text-to-SQL system based on large language models and RAG
CVE-2026-53554High· 7.3SQLBot is an intelligent Text-to-SQL system based on large language models and RAG
CVE-2026-93660Medium· 6.5SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards
CVE-2026-53557High· 7.7SQLBot is an intelligent Text-to-SQL system based on large language models and RAG