Show filters
1,748 Total Results
Displaying 151-160 of 1,748
Sort by:
Attacker Value
Unknown

CVE-2024-27906

Disclosure Date: February 29, 2024 (last updated February 14, 2025)
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerability
0
Attacker Value
Unknown

CVE-2024-24701

Disclosure Date: February 29, 2024 (last updated January 12, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects A no-code page builder for beautiful performance-based content: from n/a through 2.1.20.
Attacker Value
Unknown

CVE-2024-27133

Disclosure Date: February 23, 2024 (last updated January 23, 2025)
Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset table fields.
Attacker Value
Unknown

CVE-2024-27132

Disclosure Date: February 23, 2024 (last updated January 23, 2025)
Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over template variables.
Attacker Value
Unknown

CVE-2024-25141

Disclosure Date: February 20, 2024 (last updated February 21, 2024)
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.
0
Attacker Value
Unknown

CVE-2023-46596

Disclosure Date: February 15, 2024 (last updated January 24, 2025)
Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code. Fixed in version A32.20 (b600 and above), A32.50 (b430 and above), A32.60 (b250 and above)
Attacker Value
Unknown

CVE-2023-30767

Disclosure Date: February 14, 2024 (last updated February 15, 2024)
Improper buffer restrictions in Intel(R) Optimization for TensorFlow before version 2.13.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown

CVE-2023-50947

Disclosure Date: February 04, 2024 (last updated February 10, 2024)
IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 275665.
Attacker Value
Unknown

CVE-2023-37518

Disclosure Date: January 30, 2024 (last updated February 06, 2024)
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.
Attacker Value
Unknown

CVE-2024-0960

Disclosure Date: January 27, 2024 (last updated February 02, 2024)
A vulnerability was found in flink-extended ai-flow 0.3.1. It has been declared as critical. Affected by this vulnerability is the function cloudpickle.loads of the file \ai_flow\cli\commands\workflow_command.py. The manipulation leads to deserialization. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-252205 was assigned to this vulnerability.