Latest CVE Feed
-
9.0
CRITICALCVE-2024-28991
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.... Read more
Affected Products : access_rights_manager- Published: Sep. 12, 2024
- Modified: Sep. 16, 2024
-
8.8
HIGHCVE-2024-28990
SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI... Read more
Affected Products : access_rights_manager- Published: Sep. 12, 2024
- Modified: Sep. 16, 2024
-
9.0
CRITICALCVE-2024-45856
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within th... Read more
Affected Products : mindsdb- Published: Sep. 12, 2024
- Modified: Sep. 16, 2024
-
7.5
HIGHCVE-2024-45855
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.... Read more
Affected Products : mindsdb- Published: Sep. 12, 2024
- Modified: Sep. 16, 2024
-
8.3
HIGHCVE-2024-23599
Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
7.5
HIGHCVE-2024-21871
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products : xeon_d-2799_firmware- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
6.9
MEDIUMCVE-2023-22351
Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
6.8
MEDIUMCVE-2024-23984
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
2.5
LOWCVE-2023-25546
Out-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
7.2
HIGHCVE-2024-21781
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
6.8
MEDIUMCVE-2023-43753
Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
5.6
MEDIUMCVE-2024-24968
Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
8.7
HIGHCVE-2024-21829
Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
6.9
MEDIUMCVE-2023-23904
NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
8.7
HIGHCVE-2023-43626
Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products : atom_c5325_firmware- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
8.7
HIGHCVE-2023-41833
A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
8.7
HIGHCVE-2023-42772
Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products : xeon_d-2799_firmware- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
7.5
HIGHCVE-2024-45854
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘describe’ query is run on it.... Read more
Affected Products : mindsdb- Published: Sep. 12, 2024
- Modified: Sep. 16, 2024
-
7.5
HIGHCVE-2024-45853
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction.... Read more
Affected Products : mindsdb- Published: Sep. 12, 2024
- Modified: Sep. 16, 2024
-
8.8
HIGHCVE-2024-45852
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.... Read more
Affected Products : mindsdb- Published: Sep. 12, 2024
- Modified: Sep. 16, 2024