Vulnerabilities > Mindsdb > High

DATE CVE VULNERABILITY TITLE RISK
2024-09-12 CVE-2024-45846 Code Injection vulnerability in Mindsdb
An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server.
network
low complexity
mindsdb CWE-94
8.8
2024-09-12 CVE-2024-45847 Code Injection vulnerability in Mindsdb
An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server.
network
low complexity
mindsdb CWE-94
8.8
2024-09-12 CVE-2024-45848 Code Injection vulnerability in Mindsdb 23.12.4.0/23.12.4.1
An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server.
network
low complexity
mindsdb CWE-94
8.8
2024-09-12 CVE-2024-45849 Code Injection vulnerability in Mindsdb
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server.
network
low complexity
mindsdb CWE-94
8.8
2024-09-12 CVE-2024-45850 Code Injection vulnerability in Mindsdb
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server.
network
low complexity
mindsdb CWE-94
8.8
2024-09-12 CVE-2024-45851 Code Injection vulnerability in Mindsdb
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server.
network
low complexity
mindsdb CWE-94
8.8
2024-09-12 CVE-2024-45852 Deserialization of Untrusted Data vulnerability in Mindsdb
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.
network
low complexity
mindsdb CWE-502
8.8
2024-09-12 CVE-2024-45853 Deserialization of Untrusted Data vulnerability in Mindsdb
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction.
network
high complexity
mindsdb CWE-502
7.5
2024-09-12 CVE-2024-45854 Deserialization of Untrusted Data vulnerability in Mindsdb
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘describe’ query is run on it.
network
high complexity
mindsdb CWE-502
7.5
2024-09-12 CVE-2024-45855 Deserialization of Untrusted Data vulnerability in Mindsdb
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.
network
high complexity
mindsdb CWE-502
7.5