Записи mindsdb
22 опубликованных записей вендора mindsdb.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 72,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-502 Deserialization of Untrusted Data4
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-311 Missing Encryption of Sensitive Data1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2025-68472Proof of concept | MindsDB has improper sanitation of filepath that leads to information disclosure and DOSmindsdb · mindsdb · CWE-22 | Критическая9,1 | — | 20,3 % | 12 янв. 2026 г. |
38Наблюдать | CVE-2026-27483Proof of concept | MindsDB has Path Traversal in /api/files Leading to Remote Code Executionmindsdb · mindsdb · CWE-22 | Высокая8,8 | — | 8,8 % | 24 февр. 2026 г. |
37Наблюдать | CVE-2024-24759Proof of concept | MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebindingmindsdb · mindsdb · CWE-918 | Критическая9,1 | — | 4,9 % | 5 сент. 2024 г. |
36Наблюдать | CVE-2024-45846Эксплойта нет | An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integrationmindsdb · mindsdb · CWE-95 | Высокая8,8 | — | 2,1 % | 12 сент. 2024 г. |
36Наблюдать | CVE-2023-50731Эксплойта нет | MindsDB has arbitrary file write in file.pymindsdb · mindsdb · CWE-918 | Критическая9,1 | — | 1,0 % | 22 дек. 2023 г. |
35Наблюдать | CVE-2022-23522Эксплойта нет | Arbitrary File Write when Extracting Tarballs retrieved from a remote location using in mindsdbmindsdb · mindsdb · CWE-22 | Высокая8,8 | — | 0,9 % | 30 мар. 2023 г. |
35Наблюдать | CVE-2024-45850Эксплойта нет | An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePointmindsdb · mindsdb · CWE-95 | Высокая8,8 | — | 0,9 % | 12 сент. 2024 г. |
35Наблюдать | CVE-2024-45851Эксплойта нет | An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePointmindsdb · mindsdb · CWE-95 | Высокая8,8 | — | 0,9 % | 12 сент. 2024 г. |
35Наблюдать | CVE-2024-45849Эксплойта нет | An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePointmindsdb · mindsdb · CWE-95 | Высокая8,8 | — | 0,9 % | 12 сент. 2024 г. |
35Наблюдать | CVE-2024-45847Эксплойта нет | An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integratimindsdb · mindsdb · CWE-95 | Высокая8,8 | — | 0,9 % | 12 сент. 2024 г. |
35Наблюдать | CVE-2024-45848Эксплойта нет | An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integrationmindsdb · mindsdb · CWE-95 | Высокая8,8 | — | 0,9 % | 12 сент. 2024 г. |
35Наблюдать | CVE-2024-45852Эксплойта нет | Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model tomindsdb · mindsdb · CWE-502 | Высокая8,8 | — | 0,7 % | 12 сент. 2024 г. |
30Наблюдать | CVE-2023-30620Эксплойта нет | Arbitrary File Write when Extracting a Remotely retrieved Tarball in mindsdb/mindsdbmindsdb · mindsdb · CWE-22 | Высокая7,5 | — | 1,0 % | 21 апр. 2023 г. |
30Наблюдать | CVE-2024-45853Эксплойта нет | Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhousmindsdb · mindsdb · CWE-502 | Высокая7,5 | — | 0,5 % | 12 сент. 2024 г. |
30Наблюдать | CVE-2024-45854Эксплойта нет | Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhousmindsdb · mindsdb · CWE-502 | Высокая7,5 | — | 0,5 % | 12 сент. 2024 г. |
30Наблюдать | CVE-2024-45855Эксплойта нет | Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhousmindsdb · mindsdb · CWE-502 | Высокая7,5 | — | 0,5 % | 12 сент. 2024 г. |
26Наблюдать | CVE-2023-38699Эксплойта нет | MindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issuemindsdb · mindsdb · CWE-311 | Средняя6,5 | — | 0,3 % | 4 авг. 2023 г. |
24Наблюдать | CVE-2024-3575Эксплойта нет | Cross-site Scripting (XSS) - Stored in mindsdb/mindsdbmindsdb · mindsdb · CWE-79 | Средняя6,1 | — | 0,4 % | 15 апр. 2024 г. |
21Наблюдать | CVE-2024-45856Эксплойта нет | A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whmindsdb · mindsdb · CWE-79 | Средняя5,4 | — | 0,5 % | 12 сент. 2024 г. |
21Наблюдать | CVE-2023-49796Эксплойта нет | MindsDB Arbitrary File Write vulnerabilitymindsdb · mindsdb · CWE-20 | Средняя5,3 | — | 0,5 % | 11 дек. 2023 г. |
21Наблюдать | CVE-2023-49795Эксплойта нет | MindsDB Server-Side Request Forgery vulnerabilitymindsdb · mindsdb · CWE-918 | Средняя5,3 | — | 0,4 % | 11 дек. 2023 г. |
8Наблюдать | CVE-2026-2531Эксплойта нет | MindsDB File Upload security.py clear_filename server-side request forgerymindsdb · mindsdb · CWE-918 | Низкая2,1 | — | 0,2 % | 16 февр. 2026 г. |
- CVE-2025-6847242В плане
MindsDB has improper sanitation of filepath that leads to information disclosure and DOS
КритическаяCVSS 9,1Proof of conceptEPSS 20 %mindsdb · mindsdb12 янв. 2026 г.
- CVE-2026-2748338Наблюдать
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
ВысокаяCVSS 8,8Proof of conceptEPSS 9 %mindsdb · mindsdb24 февр. 2026 г.
- CVE-2024-2475937Наблюдать
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
КритическаяCVSS 9,1Proof of conceptEPSS 5 %mindsdb · mindsdb5 сент. 2024 г.
- CVE-2024-4584636Наблюдать
An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mindsdb · mindsdb12 сент. 2024 г.
- CVE-2023-5073136Наблюдать
MindsDB has arbitrary file write in file.py
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %mindsdb · mindsdb22 дек. 2023 г.
- CVE-2022-2352235Наблюдать
Arbitrary File Write when Extracting Tarballs retrieved from a remote location using in mindsdb
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mindsdb · mindsdb30 мар. 2023 г.
- CVE-2024-4585035Наблюдать
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mindsdb · mindsdb12 сент. 2024 г.
- CVE-2024-4585135Наблюдать
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mindsdb · mindsdb12 сент. 2024 г.
- CVE-2024-4584935Наблюдать
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mindsdb · mindsdb12 сент. 2024 г.
- CVE-2024-4584735Наблюдать
An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrati
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mindsdb · mindsdb12 сент. 2024 г.
- CVE-2024-4584835Наблюдать
An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mindsdb · mindsdb12 сент. 2024 г.
- CVE-2024-4585235Наблюдать
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mindsdb · mindsdb12 сент. 2024 г.
- CVE-2023-3062030Наблюдать
Arbitrary File Write when Extracting a Remotely retrieved Tarball in mindsdb/mindsdb
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mindsdb · mindsdb21 апр. 2023 г.
- CVE-2024-4585330Наблюдать
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhous
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mindsdb · mindsdb12 сент. 2024 г.
- CVE-2024-4585430Наблюдать
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhous
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mindsdb · mindsdb12 сент. 2024 г.
- CVE-2024-4585530Наблюдать
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhous
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mindsdb · mindsdb12 сент. 2024 г.
- CVE-2023-3869926Наблюдать
MindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issue
СредняяCVSS 6,5Эксплойта нетEPSS 0 %mindsdb · mindsdb4 авг. 2023 г.
- CVE-2024-357524Наблюдать
Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb
СредняяCVSS 6,1Эксплойта нетEPSS 0 %mindsdb · mindsdb15 апр. 2024 г.
- CVE-2024-4585621Наблюдать
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload wh
СредняяCVSS 5,4Эксплойта нетEPSS 1 %mindsdb · mindsdb12 сент. 2024 г.
- CVE-2023-4979621Наблюдать
MindsDB Arbitrary File Write vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 0 %mindsdb · mindsdb11 дек. 2023 г.
- CVE-2023-4979521Наблюдать
MindsDB Server-Side Request Forgery vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 0 %mindsdb · mindsdb11 дек. 2023 г.
- CVE-2026-25318Наблюдать
MindsDB File Upload security.py clear_filename server-side request forgery
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %mindsdb · mindsdb16 февр. 2026 г.