6.5

CVSS3.1

CVE-2023-51511 - WordPress Booster Elite for WooCommerce plugin < 7.1.3 - Authenticated Production Creation/Modifica…

Improper Authentication vulnerability in Pluggabl LLC Booster Elite for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster Elite for WooCommerce: from n/a before 7.1.3.

πŸ“… Published: June 4, 2024, 12:22 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:38 a.m.

8.1

CVSS3.1

CVE-2024-29170 -

Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure of network traffic and denial of service.

πŸ“… Published: June 4, 2024, 12:11 p.m. πŸ”„ Last Modified: Jan. 8, 2025, 4:25 p.m.

7.8

CVSS3.1

CVE-2024-37065 -

Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.

πŸ“… Published: June 4, 2024, 12:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-37064 -

Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded.

πŸ“… Published: June 4, 2024, 12:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-37063 -

A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser.

πŸ“… Published: June 4, 2024, 12:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-37062 -

Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded.

πŸ“… Published: June 4, 2024, 12:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-37061 -

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run.

πŸ“… Published: June 4, 2024, 12:02 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 2:48 p.m.

8.8

CVSS3.1

CVE-2024-37060 -

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.

πŸ“… Published: June 4, 2024, 12:02 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 2:46 p.m.

8.8

CVSS3.1

CVE-2024-37059 -

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.

πŸ“… Published: June 4, 2024, 12:01 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 2:46 p.m.

8.8

CVSS3.1

CVE-2024-37058 -

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.

πŸ“… Published: June 4, 2024, 12:01 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 2:46 p.m.
Total resulsts: 349182
Page 9588 of 34,919
Β« previous page Β» next page
Filters