Show filters
495 Total Results
Displaying 111-120 of 495
Sort by:
Attacker Value
Unknown

CVE-2022-38714

Disclosure Date: February 12, 2024 (last updated October 12, 2024)
IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privileged user. IBM X-Force ID: 235060.
Attacker Value
Unknown

CVE-2023-4637

Disclosure Date: February 05, 2024 (last updated February 13, 2024)
The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID.
Attacker Value
Unknown

CVE-2024-22160

Disclosure Date: January 31, 2024 (last updated February 06, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bradley B. Dalina Image Tag Manager allows Reflected XSS.This issue affects Image Tag Manager: from n/a through 1.5.
Attacker Value
Unknown

CVE-2024-22200

Disclosure Date: January 30, 2024 (last updated February 09, 2024)
vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulnerability, users can run the UI as an angular application. This vulnerability was patched in 4.2.0.
Attacker Value
Unknown

CVE-2024-22193

Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may accidentally create a task with sensitive input data that will then be stored unencrypted in a database. Users should ensure they set the encryption setting correctly. This vulnerability is patched in 4.2.0.
Attacker Value
Unknown

CVE-2024-21671

Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out usernames from the response time of login requests. This could aid attackers in credential attacks. Version 4.2.0 patches this vulnerability.
Attacker Value
Unknown

CVE-2024-21653

Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh config by default that permits root login with password authentication. In a proper deployment, the SSH service is not exposed so there is no risk, but not all deployments are ideal. The default should therefore be less permissive. The vulnerability can be mitigated by removing the ssh part from the docker file and rebuilding the docker image. Version 4.2.0 patches the vulnerability.
Attacker Value
Unknown

CVE-2024-21649

Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated users could inject code into algorithm environment variables, resulting in remote code execution. This vulnerability is patched in 4.2.0.
Attacker Value
Unknown

CVE-2023-7204

Disclosure Date: January 29, 2024 (last updated February 06, 2024)
The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides
Attacker Value
Unknown

CVE-2024-23750

Disclosure Date: January 22, 2024 (last updated January 30, 2024)
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.