Products: 1
Vulnerabilities: 2
Known Exploited: 0
0
Critical Level Threats
1
High Level Threats
1
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2025-47424
Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, the HTTP host header can be manipulated.
Last Modified: Apr 15, 2026
Published: May 09, 2025
CVE-2024-42056
Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.
Last Modified: Mar 02, 2026
Published: Aug 22, 2024
Items Per Page
