Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-12 CVE-2024-27320 Improper Neutralization of Formula Elements in a CSV File vulnerability in Refuel Autolabel
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files.
local
low complexity
refuel CWE-1236
7.8
2024-09-12 CVE-2024-27321 Improper Neutralization of Formula Elements in a CSV File vulnerability in Refuel Autolabel
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files.
local
low complexity
refuel CWE-1236
7.8
2024-09-12 CVE-2024-3305 Unspecified vulnerability in Utarit Soliclub
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data.This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.
network
low complexity
utarit
7.5
2024-09-12 CVE-2024-3306 Authorization Bypass Through User-Controlled Key vulnerability in Utarit Soliclub
Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.
network
low complexity
utarit CWE-639
7.5
2024-09-12 CVE-2024-45846 Code Injection vulnerability in Mindsdb
An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server.
network
low complexity
mindsdb CWE-94
8.8
2024-09-12 CVE-2024-45847 Code Injection vulnerability in Mindsdb
An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server.
network
low complexity
mindsdb CWE-94
8.8
2024-09-12 CVE-2024-45848 Code Injection vulnerability in Mindsdb 23.12.4.0/23.12.4.1
An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server.
network
low complexity
mindsdb CWE-94
8.8
2024-09-12 CVE-2024-45849 Code Injection vulnerability in Mindsdb
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server.
network
low complexity
mindsdb CWE-94
8.8
2024-09-12 CVE-2024-45850 Code Injection vulnerability in Mindsdb
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server.
network
low complexity
mindsdb CWE-94
8.8
2024-09-12 CVE-2024-45851 Code Injection vulnerability in Mindsdb
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server.
network
low complexity
mindsdb CWE-94
8.8