Vulnerabilities
179 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-0980 | A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2026-27483 | MindsDB is a platform for building artificial intelligence from enterprise data. MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authenticated attacker can exploit to achieve remote command execution. The vulnerability exists in the "Upload File" module, which corresponds to the API endpoint /api/files. Since the multipart file upload does not perform security checks on the uploaded file path, an attacker can perform path traversal by using `../` sequences in the filename field. The file write operation occurs before calling clear_filename and save_file, meaning there is no filtering of filenames or file types, allowing arbitrary content to be written to any path on the server. Version 25.9.1.1 patches the issue. NVD description · AI analysis pending | 8.8 | 11% | PoC |
| — | |
| CVE-2026-27470 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the web/ajax/status.php file within the getNearEvents() function. Event field values (specifically Name and Cause) are stored safely via parameterized queries but are later retrieved and concatenated directly into SQL WHERE clauses without escaping. An authenticated user with Events edit and view permissions can exploit this to execute arbitrary SQL queries. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2025-65791 | ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function. NOTE: this is disputed by the Supplier because there is no unsanitized user input to web/views/image.php. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2026-2531 | A security vulnerability has been detected in MindsDB up to 25.14.1. A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utilities/security.py of the component File Upload. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 74d6f0fd4b630218519a700fbee1c05c7fd4b1ed. It is best practice to apply a patch to resolve this issue. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2025-68472 | Unauthenticated path traversal in MindsDB file upload API MindsDB versions prior to 25.11.1 contain an unauthenticated path traversal vulnerability (CWE-22) in the file upload API: the PUT handler in file.py joins user-controlled JSON fields directly into a filesystem path when the request body is JSON and source_type is not "url". Unlike multipart and URL-sourced uploads, JSON uploads receive no sanitization such as a clear_filename check, so traversal sequences in the supplied name are resolved without validation. A remote, unauthenticated attacker can read arbitrary files from the server filesystem and have them moved into MindsDB's storage, exposing sensitive data such as configuration files and credentials; the CVSS 9.1 (critical) score reflects high confidentiality and availability impact. Any MindsDB deployment before 25.11.1 that exposes the file upload API over the network without authentication is affected. A public advisory and PoC reference exist (GHSA-qqhf-pm3j-96g7), EPSS estimates a 20.3% probability of exploitation within 30 days (97th percentile), but the issue is not on CISA KEV and no confirmed in-the-wild exploitation is reported in the available data. Do: Upgrade to MindsDB 25.11.1 or later, which adds sanitization for JSON file uploads. Until patched, restrict network access to the file upload API (PUT endpoint in file.py) and require authentication or reverse-proxy filtering on the filename/JSON body fields. Check MindsDB storage and server logs for signs of unexpected files moved into storage or reads of sensitive paths (e.g., configuration or credential files) via crafted upload requests. | 9.1 | 20% | PoC |
| unknown; plausibly at most thousands of internet-exposed instances | |
| CVE-2024-5026 | The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2025-46246 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Request Forgery.This issue affects CM Answers: Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Request Forgery.This issue affects CM Answers: from n/a through <= 3.3.3. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2025-46245 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site Request Forgery.This issue affects CM Ad Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site Request Forgery.This issue affects CM Ad Changer: from n/a through <= 2.0.5. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2025-29072 | An integer overflow in Nethermind Juno before v.12.05 within the Sierra bytecode decompression logic within the "cairo-lang-starknet-classes" library could allo An integer overflow in Nethermind Juno before v.12.05 within the Sierra bytecode decompression logic within the "cairo-lang-starknet-classes" library could allow remote attackers to trigger an infinite loop (and high CPU usage) by submitting a malicious Declare v2/v3 transaction. This results in a denial-of-service condition for affected Starknet full-node implementations. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2024-13684 | The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the reset_db_page() function. This makes it possible for unauthenticated attackers to reset several tables in the database like comments, themes, plugins, and more via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2025-1084 | A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2025-1082 +1 in the same advisory: …1083 | A vulnerability classified as problematic has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. A vulnerability classified as problematic has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected is an unknown function of the file /api/admin/question/edit of the component Exam Edit Handler. The manipulation of the argument title/content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.1 group max | <1% | PoC |
| — | |
| CVE-2024-13098 | The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflect The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2024-40583 +1 in the same advisory: …40582 | Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials. Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials. NVD description · AI analysis pending | 9.1 group max | <1% | PoC |
| — | |
| CVE-2024-5029 | The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, whi The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2024-52433 | Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a through <= 1.2. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2024-5030 | The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logg The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack NVD description · AI analysis pending | 3.8 | <1% | PoC |
| — | |
| CVE-2024-51679 | Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue affects Appointmind: Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue affects Appointmind: from n/a through <= 4.0.0. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-31493 | RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted pay RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system. NVD description · AI analysis pending | 6.6 | <1% |
| — | ||
| CVE-2024-45846 | An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specially crafted ‘SELECT WHERE’ clause containing Python code is run against a database created with the Weaviate engine, the code will be passed to an eval function and executed on the server. NVD description · AI analysis pending | 8.8 group max | 2% | PoC |
| — | |
| CVE-2024-5799 | The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Co The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2024-24759 | MindsDB is a platform for building artificial intelligence from enterprise data. MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch. NVD description · AI analysis pending | 9.1 | 5% | PoC |
| — | |
| CVE-2024-43360 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61. NVD description · AI analysis pending | 9.8 group max | 6% | PoC |
| — | |
| CVE-2024-5004 | The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege use The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2024-5167 | The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or w The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist menu via a CSRF attack NVD description · AI analysis pending | 8.1 | <1% | PoC |
| — | |
| CVE-2024-5028 | The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make logged in The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-3575 | Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-25730 | Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain s Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain sensitive information via PHP_SELF component in classic/views/download.php. NVD description · AI analysis pending | 8.2 | <1% |
| — | ||
| CVE-2024-29401 | xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything. xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2024-1962 | The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downlo The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2024-27515 | Osclass 5.1.2 is vulnerable to SQL Injection. Osclass 5.1.2 is vulnerable to SQL Injection. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2023-50731 | MindsDB is a SQL Server for artificial intelligence. MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/api/http/namespaces/file.py` does not validate the user-controlled name value, which is used in a temporary file name, which is afterwards opened for writing on lines 122-125, which leads to path injection. Later in the method, the temporary directory is deleted on line 151, but since we can write outside of the directory using the path injection vulnerability, the potentially dangerous file is not deleted. Arbitrary file contents can be written due to `f.write(chunk)` on line 125. Mindsdb does check later on line 149 in the `save_file` method in `file-controller.py` which calls the `_handle_source` method in `file_handler.py` if a file is of one of the types `csv`, `json`, `parquet`, `xls`, or `xlsx`. However, since the check happens after the file has already been written, the files will still exist (and will not be removed due to the path injection described earlier), just the `_handle_source` method will return an error. The same user-controlled source source is used also in another path injection sink on line 138. This leads to another path injection, which allows an attacker to delete any `zip` or `tar.gz` files on the server. NVD description · AI analysis pending | 9.1 | <1% | PoC |
| — |