Export limit exceeded: 366298 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (366298 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-37056 | 1 Lfprojects | 1 Mlflow | 2025-02-03 | 8.8 High |
| Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with. | ||||
| CVE-2024-37055 | 1 Lfprojects | 1 Mlflow | 2025-02-03 | 8.8 High |
| Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted with. | ||||
| CVE-2024-37054 | 1 Lfprojects | 1 Mlflow | 2025-02-03 | 8.8 High |
| Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with. | ||||
| CVE-2024-42422 | 1 Dell | 1 Networker | 2025-02-03 | 8.3 High |
| Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | ||||
| CVE-2024-37053 | 1 Lfprojects | 1 Mlflow | 2025-02-03 | 8.8 High |
| Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with. | ||||
| CVE-2024-37052 | 1 Lfprojects | 1 Mlflow | 2025-02-03 | 8.8 High |
| Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with. | ||||
| CVE-2018-9389 | 1 Google | 1 Android | 2025-02-03 | 5.1 Medium |
| In ip6_append_data of ip6_output.c, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2019-19245 | 1 Napc | 1 Xinet Elegant 6 Asset Library | 2025-02-02 | 9.8 Critical |
| NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used. | ||||
| CVE-2022-4118 | 1 Coinmarketstats | 1 Bitcoin \/ Altcoin Payment Gateway For Woocommerce | 2025-01-31 | 9.8 Critical |
| The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users | ||||
| CVE-2024-57775 | 1 Jfinaloa Project | 1 Jfinaloa | 2025-01-31 | 8.8 High |
| JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid. | ||||
| CVE-2024-55503 | 2 Apple, Termius | 2 Macos, Termius | 2025-01-31 | 3.3 Low |
| An issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_INSERT_LIBRARIES component. | ||||
| CVE-2024-53407 | 1 Phiewer | 1 Phiewer | 2025-01-31 | 3.3 Low |
| In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially leading to remote control and unauthorized access to sensitive user data. | ||||
| CVE-2018-9406 | 1 Google | 1 Android | 2025-01-31 | 5.5 Medium |
| In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2023-31485 | 1 Gitlab\ | 1 \ | 2025-01-31 | 5.9 Medium |
| GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks. | ||||
| CVE-2023-31483 | 1 Cauldrondevelopment | 1 Cbang | 2025-01-31 | 7.5 High |
| tar/TarFileReader.cpp in Cauldron cbang before bastet-v8.1.17 has a directory traversal during extraction that allows the attacker to create or write to files outside the current directory via a crafted tar archive. | ||||
| CVE-2022-47758 | 1 Nanoleaf | 1 Nanoleaf Firmware | 2025-01-31 | 9.8 Critical |
| Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack. | ||||
| CVE-2022-38730 | 1 Docker | 1 Desktop | 2025-01-31 | 6.3 Medium |
| Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerStartRequest class. This allows exploiting a symlink vulnerability in ..\dataRoot\network\files\local-kv.db because of a TOCTOU race condition. | ||||
| CVE-2022-37326 | 1 Docker | 1 Desktop | 2025-01-31 | 7.8 High |
| Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation. | ||||
| CVE-2022-34292 | 1 Docker | 1 Desktop | 2025-01-31 | 7.1 High |
| Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder parameter for DockerDesktop.vhdx, a similar issue to CVE-2022-31647. | ||||
| CVE-2022-31647 | 1 Docker | 1 Desktop | 2025-01-31 | 7.1 High |
| Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659. | ||||