Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.2
CVE-2026-29064
Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive ext…
Zarf
0.73.1+
HIGH 7.5
CVE-2026-27896
The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard lib…
Mcp Go Sdk
1.3.1+
MEDIUM 6.5
CVE-2026-27735
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to…
Model Context Protocol Servers
2026.1.14+
HIGH 7.5
CVE-2026-21864
Valkey-Bloom is a Rust based Valkey module which brings a Bloom Filter (Module) data type into the Valkey distributed key-value database. Prior to co…
Valkey Bloom
1.0.1+
HIGH 7.5
CVE-2026-27623
Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can…
Valkey
9.0.3+
HIGH 7.5
CVE-2026-21863
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus…
Valkey
7.2.12 / 8.0.7+
HIGH 7.1
CVE-2025-67733
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject …
Valkey
7.2.12 / 8.0.7+
HIGH 7.1
CVE-2026-25536
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client respons…
Mcp Typescript Sdk
1.26.0+
HIGH 7.0
CVE-2025-10279
In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o77…
Mlflow
3.4.0+
HIGH 8.1
CVE-2025-14279
MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server…
Mlflow
3.5.0+
HIGH 7.5
CVE-2026-0621
Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTem…
Mcp Typescript Sdk
after 1.25.1
CRITICAL 9.1
CVE-2025-68145EPSS 7%
In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository…
Model Context Protocol Servers
2025.12.18+
HIGH 8.8
CVE-2025-68143EPSS 8%
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to…
Model Context Protocol Servers
2025.9.25+
HIGH 7.1
CVE-2025-68144EPSS 7%
In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands…
Model Context Protocol Servers
2025.12.17+
HIGH 8.1
CVE-2025-66414
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) T…
Mcp Typescript Sdk
1.24.0+
HIGH 8.1
CVE-2025-66416
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context…
Mcp Python Sdk
1.23.0+
MEDIUM 5.3
CVE-2025-65105
Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --…
Apptainer
1.4.5+
CRITICAL 9.8
CVE-2025-11200
MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affecte…
Mlflow
after 2.21.0
CRITICAL 9.8
CVE-2025-11201EPSS 27%
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …
Mlflow
2025-06-10+
MEDIUM 5.5
CVE-2025-1474
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security ri…
Mlflow
2.19.0+
HIGH 7.5
CVE-2025-0453EPSS 11%
In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries…
Mlflow
No fix yet
HIGH 7.1
CVE-2025-1473
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows …
Mlflow
2.20.1+
HIGH 7.5
CVE-2024-8859
A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly …
Mlflow
Patch available
MEDIUM 5.3
CVE-2024-6838
In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its…
Mlflow
No fix yet
HIGH 7.0
CVE-2024-27134
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacke…
Mlflow
2.16.0+
MEDIUM 5.4
CVE-2024-3099
A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw c…
Mlflow
No fix yet
HIGH 7.5
CVE-2024-2928EPSS 22%
A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vu…
Mlflow
2.11.3+
HIGH 8.8
CVE-2024-0520
A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS comm…
Mlflow
2.9.0+
HIGH 8.8
CVE-2024-37058
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langch…
Mlflow
No fix yet
HIGH 8.8
CVE-2024-37059
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorc…
Mlflow
No fix yet