NA - CVE-2024-45854 - Deserialization of untrusted data can occur in...
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a...
NA - CVE-2024-45855 - Deserialization of untrusted data can occur in...
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using...
NA - CVE-2024-45856 - A cross-site scripting (XSS) vulnerability...
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project,...
NA - CVE-2024-45857 - Deserialization of untrusted data can occur in...
Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when...
Medium - CVE-2024-28990 - SolarWinds Access Rights Manager (ARM) was...
SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ...
Critical - CVE-2024-28991 - SolarWinds Access Rights Manager (ARM) was...
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service,...
No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is...
NA - CVE-2024-45824 - CVE-2024-45824 IMPACT
A remote
code...
CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and...
NA - CVE-2024-42483 - ESP-NOW Component provides a connectionless...
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not...
NA - CVE-2024-42484 - ESP-NOW Component provides a connectionless...
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An Out-of-Bound (OOB) vulnerability was discovered in the implementation of the ESP-NOW group type message because there is...