Show filters
247 Total Results
Displaying 31-40 of 247
Sort by:
Attacker Value
Unknown

CVE-2023-35625

Disclosure Date: December 12, 2023 (last updated January 12, 2025)
Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability
Attacker Value
Unknown

CVE-2023-35624

Disclosure Date: December 12, 2023 (last updated January 12, 2025)
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2023-46492

Disclosure Date: November 09, 2023 (last updated November 18, 2023)
Cross Site Scripting vulnerability in MLDB.ai v.2017.04.17.0 allows a remote attacker to execute arbitrary code via a crafted payload to the public_html/doc/index.html.
Attacker Value
Unknown

CVE-2023-40453

Disclosure Date: November 07, 2023 (last updated November 15, 2023)
Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might have a data size that causes a denial of service to a bastion node. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Attacker Value
Unknown

CVE-2023-39107

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks.
Attacker Value
Unknown

CVE-2023-20891

Disclosure Date: July 26, 2023 (last updated October 08, 2023)
The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials and can push new malicious versions of an application. In a default deployment non-admin users do not have access to the platform system audit logs.
Attacker Value
Unknown

CVE-2023-30444

Disclosure Date: April 27, 2023 (last updated October 08, 2023)
IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350.
Attacker Value
Unknown

CVE-2023-28312

Disclosure Date: April 11, 2023 (last updated January 11, 2025)
Azure Machine Learning Information Disclosure Vulnerability
Attacker Value
Unknown

CVE-2023-26784

Disclosure Date: March 16, 2023 (last updated October 08, 2023)
SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter.
Attacker Value
Unknown

CVE-2023-26511

Disclosure Date: March 14, 2023 (last updated October 08, 2023)
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system.