Vulnerability index

Browse CVEs

103 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zarf HIGH 8.2
CVE-2026-29064

Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive ext…

Fix: 0.73.1+
Fix from $1,950 2026-03-06
Mcp Go Sdk HIGH 7.5
CVE-2026-27896

The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard lib…

Fix: 1.3.1+
Fix from $1,950 2026-02-26
Model Context Protocol Servers MEDIUM 6.5
CVE-2026-27735

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to…

Fix: 2026.1.14+
Fix from $1,600 2026-02-26
Valkey Bloom HIGH 7.5
CVE-2026-21864

Valkey-Bloom is a Rust based Valkey module which brings a Bloom Filter (Module) data type into the Valkey distributed key-value database. Prior to co…

Fix: 1.0.1+
Fix from $1,950 2026-02-24
Valkey HIGH 7.5
CVE-2026-27623

Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can…

Fix: 9.0.3+
Fix from $1,950 2026-02-23
Valkey HIGH 7.5
CVE-2026-21863

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus…

Fix: 7.2.12 / 8.0.7+
Fix from $1,950 2026-02-23
Valkey HIGH 7.1
CVE-2025-67733

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject …

Fix: 7.2.12 / 8.0.7+
Fix from $1,950 2026-02-23
Mcp Typescript Sdk HIGH 7.1
CVE-2026-25536

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client respons…

Fix: 1.26.0+
Fix from $1,950 2026-02-04
Mlflow HIGH 7.0
CVE-2025-10279

In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o77…

Fix: 3.4.0+
Fix from $1,950 2026-02-02
Mlflow HIGH 8.1
CVE-2025-14279

MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server…

Fix: 3.5.0+
Fix from $1,950 2026-01-12
Mcp Typescript Sdk HIGH 7.5
CVE-2026-0621

Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTem…

Fix: after 1.25.1
Fix from $1,950 2026-01-05
Model Context Protocol Servers CRITICAL 9.1
CVE-2025-68145EPSS 7%

In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository…

Fix: 2025.12.18+
Fix from $2,300 2025-12-17
Model Context Protocol Servers HIGH 8.8
CVE-2025-68143EPSS 8%

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to…

Fix: 2025.9.25+
Fix from $1,950 2025-12-17
Model Context Protocol Servers HIGH 7.1
CVE-2025-68144EPSS 7%

In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands…

Fix: 2025.12.17+
Fix from $1,950 2025-12-17
Mcp Typescript Sdk HIGH 8.1
CVE-2025-66414

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) T…

Fix: 1.24.0+
Fix from $1,950 2025-12-02
Mcp Python Sdk HIGH 8.1
CVE-2025-66416

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context…

Fix: 1.23.0+
Fix from $1,950 2025-12-02
Apptainer MEDIUM 5.3
CVE-2025-65105

Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --…

Fix: 1.4.5+
Fix from $1,600 2025-12-02
Mlflow CRITICAL 9.8
CVE-2025-11200

MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affecte…

Fix: after 2.21.0
Fix from $2,300 2025-10-29
Mlflow CRITICAL 9.8
CVE-2025-11201EPSS 27%

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …

Fix: 2025-06-10+
Fix from $2,300 2025-10-29
Mlflow MEDIUM 5.5
CVE-2025-1474

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security ri…

Fix: 2.19.0+
Fix from $1,600 2025-03-20
Mlflow HIGH 7.5
CVE-2025-0453EPSS 11%

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries…

No fix yet
Fix from $1,950 2025-03-20
Mlflow HIGH 7.1
CVE-2025-1473

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows …

Fix: 2.20.1+
Fix from $1,950 2025-03-20
Mlflow HIGH 7.5
CVE-2024-8859

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly …

Patch available
Fix from $1,950 2025-03-20
Mlflow MEDIUM 5.3
CVE-2024-6838

In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its…

No fix yet
Fix from $1,600 2025-03-20
Mlflow HIGH 7.0
CVE-2024-27134

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacke…

Fix: 2.16.0+
Fix from $1,950 2024-11-25
Mlflow MEDIUM 5.4
CVE-2024-3099

A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw c…

No fix yet
Fix from $1,600 2024-06-06
Mlflow HIGH 7.5
CVE-2024-2928EPSS 22%

A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vu…

Fix: 2.11.3+
Fix from $1,950 2024-06-06
Mlflow HIGH 8.8
CVE-2024-0520

A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS comm…

Fix: 2.9.0+
Fix from $1,950 2024-06-06
Mlflow HIGH 8.8
CVE-2024-37058

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langch…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37059

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorc…

No fix yet
Fix from $1,950 2024-06-04