Show filters
495 Total Results
Displaying 111-120 of 495
Sort by:
Attacker Value
Unknown
CVE-2022-38714
Disclosure Date: February 12, 2024 (last updated October 12, 2024)
IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privileged user. IBM X-Force ID: 235060.
0
Attacker Value
Unknown
CVE-2023-4637
Disclosure Date: February 05, 2024 (last updated February 13, 2024)
The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID.
0
Attacker Value
Unknown
CVE-2024-22160
Disclosure Date: January 31, 2024 (last updated February 06, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bradley B. Dalina Image Tag Manager allows Reflected XSS.This issue affects Image Tag Manager: from n/a through 1.5.
0
Attacker Value
Unknown
CVE-2024-22200
Disclosure Date: January 30, 2024 (last updated February 09, 2024)
vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulnerability, users can run the UI as an angular application. This vulnerability was patched in 4.2.0.
0
Attacker Value
Unknown
CVE-2024-22193
Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may accidentally create a task with sensitive input data that will then be stored unencrypted in a database. Users should ensure they set the encryption setting correctly. This vulnerability is patched in 4.2.0.
0
Attacker Value
Unknown
CVE-2024-21671
Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out usernames from the response time of login requests. This could aid attackers in credential attacks. Version 4.2.0 patches this vulnerability.
0
Attacker Value
Unknown
CVE-2024-21653
Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh config by default that permits root login with password authentication. In a proper deployment, the SSH service is not exposed so there is no risk, but not all deployments are ideal. The default should therefore be less permissive. The vulnerability can be mitigated by removing the ssh part from the docker file and rebuilding the docker image. Version 4.2.0 patches the vulnerability.
0
Attacker Value
Unknown
CVE-2024-21649
Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated users could inject code into algorithm environment variables, resulting in remote code execution. This vulnerability is patched in 4.2.0.
0
Attacker Value
Unknown
CVE-2023-7204
Disclosure Date: January 29, 2024 (last updated February 06, 2024)
The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides
0
Attacker Value
Unknown
CVE-2024-23750
Disclosure Date: January 22, 2024 (last updated January 30, 2024)
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.
0