|
309431
|
7.5 |
HIGH
Network
|
nvidia
|
mlnx-os mlnx-gw onyx nvda-os_xc
|
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch…
|
NVD-CWE-Other
|
CVE-2024-0101
|
2024-09-17 04:24 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309432
|
8.8 |
HIGH
Network
|
solarwinds
|
access_rights_manager
|
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, r…
|
NVD-CWE-noinfo
|
CVE-2024-28991
|
2024-09-17 03:06 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309433
|
9.8 |
CRITICAL
Network
|
solarwinds
|
access_rights_manager
|
SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-28990
|
2024-09-17 03:05 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309434
|
5.4 |
MEDIUM
Network
|
mindsdb
|
mindsdb
|
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, o…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45856
|
2024-09-17 03:04 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309435
|
7.5 |
HIGH
Network
|
mindsdb
|
mindsdb
|
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘fi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-45855
|
2024-09-17 03:03 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309436
|
7.5 |
HIGH
Network
|
mindsdb
|
mindsdb
|
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘descri…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-45854
|
2024-09-17 03:02 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309437
|
7.5 |
HIGH
Network
|
mindsdb
|
mindsdb
|
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-45853
|
2024-09-17 02:59 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309438
|
8.8 |
HIGH
Network
|
mindsdb
|
mindsdb
|
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-45852
|
2024-09-17 02:51 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309439
|
5.5 |
MEDIUM
Local
|
adobe
|
indesign
|
InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-34127
|
2024-09-17 02:48 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309440
|
8.8 |
HIGH
Network
|
mindsdb
|
mindsdb
|
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases crea…
|
CWE-94
Code Injection
|
CVE-2024-45851
|
2024-09-17 02:36 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|