Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-3198
MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically,…
Mlflow
No fix yet
CRITICAL 9.8
CVE-2026-0545
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a…
Mlflow
Mitigation only
HIGH 7.8
CVE-2026-0596
A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into…
Mlflow
No fix yet
HIGH 7.1
CVE-2025-15381
In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission valida…
Mlflow
No fix yet
HIGH 7.5
CVE-2025-0453EPSS 11%
In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries…
Mlflow
No fix yet
MEDIUM 5.3
CVE-2024-6838
In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its…
Mlflow
No fix yet
MEDIUM 5.4
CVE-2024-3099
A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw c…
Mlflow
No fix yet
HIGH 8.8
CVE-2024-37058
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langch…
Mlflow
No fix yet
HIGH 8.8
CVE-2024-37059
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorc…
Mlflow
No fix yet
HIGH 8.8
CVE-2024-37060
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe…
Mlflow
No fix yet
HIGH 8.8
CVE-2024-37061
Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execu…
Mlflow
No fix yet
HIGH 8.8
CVE-2024-37054
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc…
Mlflow
No fix yet
HIGH 8.8
CVE-2024-37055
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdar…
Mlflow
No fix yet
HIGH 8.8
CVE-2024-37056
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded Light…
Mlflow
No fix yet
HIGH 8.8
CVE-2024-37057
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Ten…
Mlflow
No fix yet
HIGH 8.8
CVE-2024-37052
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit…
Mlflow
No fix yet
HIGH 8.8
CVE-2024-37053
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit…
Mlflow
No fix yet
CRITICAL 9.8
CVE-2023-6014
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
Mlflow
No fix yet
CRITICAL 9.8
CVE-2023-6018EPSS 48%
An attacker can overwrite any file on the server hosting MLflow without any authentication.
Mlflow
No fix yet
HIGH 7.5
CVE-2022-46397
FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable IV with C…
Vector Packet Processor
Mitigation only