Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-27483EPSS 11%
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability i…
Mindsdb
25.9.1.1+
HIGH 7.3
CVE-2026-2531
A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utili…
Mindsdb
after 25.14.1
CRITICAL 9.1
CVE-2025-68472EPSS 20%
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the f…
Mindsdb
25.11.1+
HIGH 7.5
CVE-2024-45855
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model …
Mindsdb
No fix yet
MEDIUM 5.4
CVE-2024-45856
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a …
Mindsdb
No fix yet
HIGH 8.8
CVE-2024-45851
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integrat…
Mindsdb
24.7.4.1+
HIGH 8.8
CVE-2024-45852
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbi…
Mindsdb
No fix yet
HIGH 7.5
CVE-2024-45853
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model …
Mindsdb
No fix yet
HIGH 7.5
CVE-2024-45854
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model …
Mindsdb
No fix yet
HIGH 8.8
CVE-2024-45847
An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is in…
Mindsdb
24.7.4.1+
HIGH 8.8
CVE-2024-45848
An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is insta…
Mindsdb
24.7.4.1+
HIGH 8.8
CVE-2024-45849
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integrat…
Mindsdb
24.7.4.1+
HIGH 8.8
CVE-2024-45850
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integrat…
Mindsdb
24.7.4.1+
HIGH 8.8
CVE-2024-45846
An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is insta…
Mindsdb
24.7.4.1+
CRITICAL 9.1
CVE-2024-24759
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-sid…
Mindsdb
23.12.4.2+
MEDIUM 6.1
CVE-2024-3575
Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb
Mindsdb
No fix yet
CRITICAL 9.1
CVE-2023-50731
MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/api/http/namespaces/file.py` do…
Mindsdb
23.11.4.1+
MEDIUM 5.3
CVE-2023-49796
MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a limited file write vulnerability in `file.py…
Mindsdb
Patch available
MEDIUM 5.3
CVE-2023-49795
MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in…
Mindsdb
23.11.4.1+
MEDIUM 6.5
CVE-2023-38699
MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `ver…
Mindsdb
23.7.4.0+
HIGH 7.5
CVE-2023-30620
mindsdb is a Machine Learning platform to help developers build AI solutions. In affected versions an unsafe extraction is being performed using `tar…
Mindsdb
after 23.1.5.0
HIGH 8.8
CVE-2022-23522
MindsDB is an open source machine learning platform. An unsafe extraction is being performed using `shutil.unpack_archive()` from a remotely retrieve…
Mindsdb
22.11.4.3+