Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-12 | CVE-2024-45852 | Deserialization of Untrusted Data vulnerability in Mindsdb Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with. | 8.8 |
2024-09-12 | CVE-2024-45853 | Deserialization of Untrusted Data vulnerability in Mindsdb Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction. | 7.5 |
2024-09-12 | CVE-2024-45854 | Deserialization of Untrusted Data vulnerability in Mindsdb Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘describe’ query is run on it. | 7.5 |
2024-09-12 | CVE-2024-45855 | Deserialization of Untrusted Data vulnerability in Mindsdb Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it. | 7.5 |
2024-09-12 | CVE-2024-45856 | Cross-site Scripting vulnerability in Mindsdb A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI. | 5.4 |
2024-09-12 | CVE-2024-8749 | SQL Injection vulnerability in I-Doit 28 SQL injection vulnerability in idoit pro version 28. | 7.5 |
2024-09-12 | CVE-2024-8750 | Cross-site Scripting vulnerability in I-Doit 28 Cross-site Scripting (XSS) vulnerability in idoit pro version 28. | 6.1 |
2024-09-12 | CVE-2024-2010 | Cross-site Scripting vulnerability in Tebilisim V5 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows Reflected XSS.This issue affects V5: before 6.2. | 6.1 |
2024-09-12 | CVE-2024-8522 | SQL Injection vulnerability in Thimpress Learnpress The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2024-09-12 | CVE-2024-8529 | SQL Injection vulnerability in Thimpress Learnpress The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |