Alldata is a modestly scoped vendor whose vulnerability footprint centers on a single widely deployed automotive repair and maintenance-documentation platform. Vulnerabilities affecting the product skew strongly toward critical severity and recur across a set of high-risk weakness classes including untrusted deserialization, improper access control, path traversal, command injection, and SQL injection—flaws that reflect both the application's data-handling scope and common pitfalls in web-accessible business software. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alldata over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-29432CRITICAL Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas. | Apr 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-27604CRITICAL Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized. | Apr 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-29433CRITICAL A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data. | Apr 1, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-27602CRITICAL Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module. | Apr 2, 2024 | 9.1 | 25 | NO | NO |
CVE-2024-29434HIGH An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file. | Apr 2, 2024 | 8.3 | 22 | NO | NO |
CVE-2024-27605HIGH Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system. | Apr 2, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-29435MEDIUM An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter. | Apr 1, 2024 | 4.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alldata.
Media articles that mention a CVE ID that affects a product developed by Alldata — matched by CVE ID, not by vendor name.