Перейти к содержимому
Noroxi

Записи mindsdb

22 опубликованных записей вендора mindsdb.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
72,7 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

22 записей
  • CVE-2025-68472
    42В плане

    MindsDB has improper sanitation of filepath that leads to information disclosure and DOS

    КритическаяCVSS 9,1Proof of conceptEPSS 20 %

    mindsdb · mindsdb12 янв. 2026 г.

  • CVE-2026-27483
    38Наблюдать

    MindsDB has Path Traversal in /api/files Leading to Remote Code Execution

    ВысокаяCVSS 8,8Proof of conceptEPSS 9 %

    mindsdb · mindsdb24 февр. 2026 г.

  • CVE-2024-24759
    37Наблюдать

    MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding

    КритическаяCVSS 9,1Proof of conceptEPSS 5 %

    mindsdb · mindsdb5 сент. 2024 г.

  • CVE-2024-45846
    36Наблюдать

    An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    mindsdb · mindsdb12 сент. 2024 г.

  • CVE-2023-50731
    36Наблюдать

    MindsDB has arbitrary file write in file.py

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    mindsdb · mindsdb22 дек. 2023 г.

  • CVE-2022-23522
    35Наблюдать

    Arbitrary File Write when Extracting Tarballs retrieved from a remote location using in mindsdb

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mindsdb · mindsdb30 мар. 2023 г.

  • CVE-2024-45850
    35Наблюдать

    An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mindsdb · mindsdb12 сент. 2024 г.

  • CVE-2024-45851
    35Наблюдать

    An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mindsdb · mindsdb12 сент. 2024 г.

  • CVE-2024-45849
    35Наблюдать

    An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mindsdb · mindsdb12 сент. 2024 г.

  • CVE-2024-45847
    35Наблюдать

    An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrati

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mindsdb · mindsdb12 сент. 2024 г.

  • CVE-2024-45848
    35Наблюдать

    An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mindsdb · mindsdb12 сент. 2024 г.

  • CVE-2024-45852
    35Наблюдать

    Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mindsdb · mindsdb12 сент. 2024 г.

  • CVE-2023-30620
    30Наблюдать

    Arbitrary File Write when Extracting a Remotely retrieved Tarball in mindsdb/mindsdb

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    mindsdb · mindsdb21 апр. 2023 г.

  • CVE-2024-45853
    30Наблюдать

    Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhous

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    mindsdb · mindsdb12 сент. 2024 г.

  • CVE-2024-45854
    30Наблюдать

    Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhous

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    mindsdb · mindsdb12 сент. 2024 г.

  • CVE-2024-45855
    30Наблюдать

    Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhous

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    mindsdb · mindsdb12 сент. 2024 г.

  • CVE-2023-38699
    26Наблюдать

    MindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issue

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    mindsdb · mindsdb4 авг. 2023 г.

  • CVE-2024-3575
    24Наблюдать

    Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    mindsdb · mindsdb15 апр. 2024 г.

  • CVE-2024-45856
    21Наблюдать

    A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload wh

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    mindsdb · mindsdb12 сент. 2024 г.

  • CVE-2023-49796
    21Наблюдать

    MindsDB Arbitrary File Write vulnerability

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    mindsdb · mindsdb11 дек. 2023 г.

  • CVE-2023-49795
    21Наблюдать

    MindsDB Server-Side Request Forgery vulnerability

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    mindsdb · mindsdb11 дек. 2023 г.

  • CVE-2026-2531
    8Наблюдать

    MindsDB File Upload security.py clear_filename server-side request forgery

    НизкаяCVSS 2,1Эксплойта нетEPSS 0 %

    mindsdb · mindsdb16 февр. 2026 г.