Skip to content
Noroxi

mindsdb records

22 published records for vendor mindsdb.

All records

22 records
  • MindsDB has improper sanitation of filepath that leads to information disclosure and DOS

    CriticalCVSS 9.1Proof of conceptEPSS 20%

    mindsdb · mindsdbJan 12, 2026

  • MindsDB has Path Traversal in /api/files Leading to Remote Code Execution

    HighCVSS 8.8Proof of conceptEPSS 9%

    mindsdb · mindsdbFeb 24, 2026

  • MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding

    CriticalCVSS 9.1Proof of conceptEPSS 5%

    mindsdb · mindsdbSep 5, 2024

  • An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration

    HighCVSS 8.8No exploitEPSS 2%

    mindsdb · mindsdbSep 12, 2024

  • MindsDB has arbitrary file write in file.py

    CriticalCVSS 9.1No exploitEPSS 1%

    mindsdb · mindsdbDec 22, 2023

  • Arbitrary File Write when Extracting Tarballs retrieved from a remote location using in mindsdb

    HighCVSS 8.8No exploitEPSS 1%

    mindsdb · mindsdbMar 30, 2023

  • An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint

    HighCVSS 8.8No exploitEPSS 1%

    mindsdb · mindsdbSep 12, 2024

  • An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint

    HighCVSS 8.8No exploitEPSS 1%

    mindsdb · mindsdbSep 12, 2024

  • An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint

    HighCVSS 8.8No exploitEPSS 1%

    mindsdb · mindsdbSep 12, 2024

  • An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrati

    HighCVSS 8.8No exploitEPSS 1%

    mindsdb · mindsdbSep 12, 2024

  • An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration

    HighCVSS 8.8No exploitEPSS 1%

    mindsdb · mindsdbSep 12, 2024

  • Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to

    HighCVSS 8.8No exploitEPSS 1%

    mindsdb · mindsdbSep 12, 2024

  • Arbitrary File Write when Extracting a Remotely retrieved Tarball in mindsdb/mindsdb

    HighCVSS 7.5No exploitEPSS 1%

    mindsdb · mindsdbApr 21, 2023

  • Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhous

    HighCVSS 7.5No exploitEPSS 1%

    mindsdb · mindsdbSep 12, 2024

  • Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhous

    HighCVSS 7.5No exploitEPSS 1%

    mindsdb · mindsdbSep 12, 2024

  • Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhous

    HighCVSS 7.5No exploitEPSS 1%

    mindsdb · mindsdbSep 12, 2024

  • MindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issue

    MediumCVSS 6.5No exploitEPSS 0%

    mindsdb · mindsdbAug 4, 2023

  • CVE-2024-3575
    24Monitor

    Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb

    MediumCVSS 6.1No exploitEPSS 0%

    mindsdb · mindsdbApr 15, 2024

  • A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload wh

    MediumCVSS 5.4No exploitEPSS 1%

    mindsdb · mindsdbSep 12, 2024

  • MindsDB Arbitrary File Write vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    mindsdb · mindsdbDec 11, 2023

  • MindsDB Server-Side Request Forgery vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    mindsdb · mindsdbDec 11, 2023

  • MindsDB File Upload security.py clear_filename server-side request forgery

    LowCVSS 2.1No exploitEPSS 0%

    mindsdb · mindsdbFeb 16, 2026