Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Eng

First CVE: Mar 9, 2014Active for: 12 yearsTotal CVEs: 30
39.2
VTI Score
Medium

Eng's vulnerability footprint, while concentrated in a small product portfolio, reaches a more prominent standing than its product count suggests, centered on the Knowage and SpagoBI business-intelligence and reporting platforms. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a notable tendency toward public exploit availability, reflecting the web-facing nature and data-access privileges of these analytics platforms. The exposure recurs through a durable pattern of application-layer weaknesses: cross-site scripting, authentication bypasses, code injection, path traversal, and injection flaws that are characteristic of complex web applications handling user input and file system operations. Defenders should prioritize patches for these platforms, particularly in internet-reachable deployments, given the combination of serious severity and the availability of exploit tooling. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
More Total CVEs than 97% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Eng over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 9, 2014
12 years ago
Most Recent CVE
Jan 7, 2026
198 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-6231HIGH
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
Jan 10, 20208.836NOYES
CVE-2013-6234HIGH
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an execu
Nov 22, 20198.032NOYES
CVE-2025-59954CRITICAL
Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using an unsafe org.apache.commons.jxp
Sep 30, 20259.831NONO
CVE-2021-30213MEDIUM
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetServic
May 12, 20216.130NOYES
CVE-2019-13188CRITICAL
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
Sep 5, 20199.830NONO
CVE-2024-54794CRITICAL
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
Jan 21, 20259.129NONO
CVE-2021-30214MEDIUM
Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.
May 12, 20215.429NONO
CVE-2021-30055HIGH
A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' parameter when running a report.
Apr 5, 20218.827NONO
CVE-2019-13348HIGH
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
Aug 28, 20198.827NONO
CVE-2024-57971CRITICAL
DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI Name.
Feb 16, 20259.125NONO
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
67%
17%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (90.0%)
Unknown3 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (90.0%)
High0 (0.0%)
Unknown3 (10.0%)
User Interaction
None14 (46.7%)
Unknown3 (10.0%)
Required13 (43.3%)
Privileges Required
Low12 (40.0%)
High3 (10.0%)
None12 (40.0%)
Unknown3 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.3% of CVEs· 95th percentile
ExploitDB
4 CVEs
13.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Eng.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Eng — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Eng's Products

View all 2 CNAs →

Top CWEs