Davinci ProjectCVEs & Vulnerabilities
3 CVEs affecting Davinci Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
davinci 3
CVE-2023-31847MEDIUM
In davinci 0.3.0-rc after logging in, the user can connect to the mysql malicious server by controlling the data source to read arbitrary files on the client side.
17 May 2023
6.5
CVSS
CVE-2023-31848HIGH
davinci 0.3.0-rc is vulnerable to Server-side request forgery (SSRF).
17 May 2023
8.8
CVSS
CVE-2023-24206CRITICAL
Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function.
27 Feb 2023
9.8
CVSS
← PrevPage 1 / 1Next →