9

CVSS3.1

CVE-2024-28991 - SolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code Execution

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.

๐Ÿ“… Published: Sept. 12, 2024, 1:17 p.m. ๐Ÿ”„ Last Modified: Sept. 17, 2024, 3:55 a.m.

6.3

CVSS3.1

CVE-2024-28990 - SolarWinds Access Rights Manager (ARM) Hardcoded Credentials Authentication Bypass Vulnerability

SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinatinโ€ฆ

๐Ÿ“… Published: Sept. 12, 2024, 1:16 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2024, 6:05 p.m.

8.8

CVSS4.0

CVE-2024-3306 - IDOR in Utarit Information's SoliClub

Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.

๐Ÿ“… Published: Sept. 12, 2024, 1:06 p.m. ๐Ÿ”„ Last Modified: Sept. 19, 2024, 2:43 p.m.

9

CVSS3.1

CVE-2024-45856 -

A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.

๐Ÿ“… Published: Sept. 12, 2024, 1:05 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2024, 6:04 p.m.

7.1

CVSS3.1

CVE-2024-45855 -

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded โ€˜inhouseโ€™ model to run arbitrary code on the server when using โ€˜finetuneโ€™ on it.

๐Ÿ“… Published: Sept. 12, 2024, 1:04 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2024, 6:03 p.m.

7.1

CVSS3.1

CVE-2024-45854 -

Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded โ€˜inhouseโ€™ model to run arbitrary code on the server when a โ€˜describeโ€™ query is run on it.

๐Ÿ“… Published: Sept. 12, 2024, 1:03 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2024, 6:02 p.m.

8.8

CVSS4.0

CVE-2024-3305 - IDOR in Utarit Information's SoliClub

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data. This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.

๐Ÿ“… Published: Sept. 12, 2024, 1:03 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 1:15 p.m.

7.1

CVSS3.1

CVE-2024-45853 -

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded โ€˜inhouseโ€™ model to run arbitrary code on the server when used for a prediction.

๐Ÿ“… Published: Sept. 12, 2024, 1:03 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2024, 5:59 p.m.

8.8

CVSS3.1

CVE-2024-45852 -

Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.

๐Ÿ“… Published: Sept. 12, 2024, 1:02 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2024, 5:51 p.m.

8.8

CVSS3.1

CVE-2024-45851 -

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an โ€˜INSERTโ€™ query can be used for list item creation. If such a querโ€ฆ

๐Ÿ“… Published: Sept. 12, 2024, 1:01 p.m. ๐Ÿ”„ Last Modified: Sept. 16, 2024, 5:36 p.m.
Total resulsts: 349182
Page 8585 of 34,919
ยซ previous page ยป next page
Filters