Davinci Project's vulnerability footprint is concentrated in its Davinci product and reflects a narrow, specialized scope within the vendor's portfolio. The recurring exposure centers on input-handling and server-interaction weaknesses including SQL injection and server-side request forgery, which are characteristic of web-facing application architectures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Davinci Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24206CRITICAL Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function. | Feb 27, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-31848HIGH davinci 0.3.0-rc is vulnerable to Server-side request forgery (SSRF). | May 17, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-31847MEDIUM In davinci 0.3.0-rc after logging in, the user can connect to the mysql malicious server by controlling the data source to read arbitrary files on the client side. | May 17, 2023 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Davinci Project.
Media articles that mention a CVE ID that affects a product developed by Davinci Project — matched by CVE ID, not by vendor name.