ZenML是一个可扩展的开源 MLOps 框架,用于创建可移植的、可用于生产的机器学习管道。 ZenML v0.55.4版本存在安全漏洞,该漏洞源于在 /materializers/cloudpickle_materializer.py 中的 load函数中包含任意文件上传漏洞,允许攻击者通过上传精心设计的文件来执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-32282 | 7.2 HIGH | Intel Processors 安全漏洞 |
| CVE-2023-32666 | 7.2 HIGH | Intel Xeon Processors 安全漏洞 |
| CVE-2023-35191 | 6.8 MEDIUM | Intel SPS 资源管理错误漏洞 |
| CVE-2023-32633 | 6.7 MEDIUM | Intel Converged Security and Management Engine 输入验证错误漏洞 |
| CVE-2023-28389 | 6.7 MEDIUM | Intel Converged Security and Management Engine 安全漏洞 |
| CVE-2023-28746 | 6.5 MEDIUM | Intel Atom Processors 安全漏洞 |
| CVE-2023-39368 | 6.5 MEDIUM | Intel Processors 安全漏洞 |
| CVE-2023-22655 | 6.1 MEDIUM | Intel Xeon Processors 安全漏洞 |
| CVE-2023-38575 | 5.5 MEDIUM | Intel Processors 安全漏洞 |
| CVE-2023-43490 | 5.3 MEDIUM | Intel Xeon D Processors 安全漏洞 |
| CVE-2023-27502 | 3.3 LOW | Intel Local Manageability Service 日志信息泄露漏洞 |
| CVE-2024-26503 | Open eClass Platform 安全漏洞 | |
| CVE-2024-26475 | radare2 安全漏洞 | |
| CVE-2023-50677 | NETGEAR DGND4000 安全漏洞 | |
| CVE-2023-42286 | EyouCms 安全漏洞 | |
| CVE-2024-28425 | Graykite 安全漏洞 | |
| CVE-2024-28423 | Airflow-Diagrams 安全漏洞 | |
| CVE-2024-25139 | TP-LINK Omada ER605 安全漏洞 | |
| CVE-2024-28418 | Webedition 安全漏洞 | |
| CVE-2024-28417 | Webedition 跨站脚本漏洞 |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet