Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Datagear

First CVE: Mar 22, 2023Active for: 3 yearsTotal CVEs: 9

Datagear develops a data visualization and analytics platform whose vulnerability profile, despite a narrow product scope, ranks notably in the vulnerability landscape. Vulnerabilities affecting the product skew strongly toward critical-severity outcomes and recur across a consistent set of weaknesses centered on input handling and data processing: cross-site scripting, injection, SQL injection, untrusted deserialization, and path traversal all reflect the parser and query-execution demands of a web-based analytics engine. Defenders deploying this product should prioritize patch cycles for these input-validation and deserialization classes; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Datagear over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 22, 2023
3 years ago
Most Recent CVE
Dec 10, 2025
226 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-1571CRITICAL
A vulnerability, which was classified as critical, was found in DataGear up to 4.5.0. This affects an unknown part of the file /analysisProject/pagingQueryData. The manipulation of
Mar 22, 20239.829NONO
CVE-2025-65792CRITICAL
DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.
Dec 10, 20259.128NONO
CVE-2023-7299CRITICAL
A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code of the file /dataSet/resolveSql. The manipulation of the
Nov 23, 20249.826NONO
CVE-2024-37759CRITICAL
DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing interface.
Jun 24, 20249.826NONO
CVE-2024-7552HIGH
A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file Conversio
Aug 6, 20248.824NONO
CVE-2023-2042HIGH
A vulnerability, which was classified as problematic, has been found in DataGear up to 4.7.0/5.1.0. Affected by this issue is some unknown functionality of the component JDBC Serve
Apr 14, 20238.822NONO
CVE-2023-1573MEDIUM
A vulnerability was found in DataGear up to 1.11.1 and classified as problematic. This issue affects some unknown processing of the component Graph Dataset Handler. The manipulatio
Mar 22, 20236.120NONO
CVE-2023-1572MEDIUM
A vulnerability has been found in DataGear up to 1.11.1 and classified as problematic. This vulnerability affects unknown code of the component Plugin Handler. The manipulation lea
Mar 22, 20235.419NONO
CVE-2023-1772MEDIUM
A vulnerability was found in DataGear up to 4.5.1. It has been classified as problematic. This affects an unknown part of the component Diagram Type Handler. The manipulation leads
Mar 31, 20234.818NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
22%
44%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low3 (33.3%)
High1 (11.1%)
None5 (55.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Datagear.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Datagear — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Datagear's Products

View all 2 CNAs →

Top CWEs