Show filters
1,748 Total Results
Displaying 101-110 of 1,748
Sort by:
Attacker Value
Unknown

CVE-2024-37052

Disclosure Date: June 04, 2024 (last updated February 04, 2025)
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.
Attacker Value
Unknown

CVE-2024-35631

Disclosure Date: June 03, 2024 (last updated June 03, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.45.7212.
0
Attacker Value
Unknown

CVE-2024-5311

Disclosure Date: June 03, 2024 (last updated January 05, 2025)
DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records.
0
Attacker Value
Unknown

CVE-2024-28793

Disclosure Date: May 28, 2024 (last updated May 29, 2024)
IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286830.
0
Attacker Value
Unknown

CVE-2024-4263

Disclosure Date: May 16, 2024 (last updated February 04, 2025)
A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an experiment can delete any artifacts. This issue arises due to the lack of proper validation for DELETE requests by users with EDIT permissions, allowing them to perform unauthorized deletions of artifacts. The vulnerability specifically affects the handling of artifact deletions within the application, as demonstrated by the ability of a low privilege user to delete a directory inside an artifact using a DELETE request, despite the official documentation stating that users with EDIT permission can only read and update artifacts, not delete them.
Attacker Value
Unknown

CVE-2024-3848

Disclosure Date: May 16, 2024 (last updated January 25, 2025)
A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the fragment, effectively skipping validation. This allows an attacker to construct a URL that, when processed, ignores the protocol scheme and uses the provided path for filesystem access. As a result, an attacker can read arbitrary files, including sensitive information such as SSH and cloud keys, by exploiting the way the application converts the URL into a filesystem path. The issue stems from insufficient validation of the fragment portion of the URL, leading to arbitrary file read through path traversal.
Attacker Value
Unknown

CVE-2024-4893

Disclosure Date: May 15, 2024 (last updated January 05, 2025)
DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.
0
Attacker Value
Unknown

CVE-2024-32077

Disclosure Date: May 14, 2024 (last updated February 14, 2025)
Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.
Attacker Value
Unknown

CVE-2024-32078

Disclosure Date: April 24, 2024 (last updated April 25, 2024)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.44.7212.
0
Attacker Value
Unknown

CVE-2024-32872

Disclosure Date: April 24, 2024 (last updated April 25, 2024)
Umbraco workflow provides workflows for the Umbraco content management system. Prior to versions 10.3.9, 12.2.6, and 13.0.6, an Umbraco Backoffice user can modify requests to a particular API endpoint to include SQL, which will be executed by the server. Umbraco Workflow versions 10.3.9, 12.2.6, 13.0.6, as well as Umbraco Plumber version 10.1.2, contain a patch for this issue.
0