Vulnerability index

Browse CVEs

103 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2026-29064 Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive ext… Zarf 0.73.1+ Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-27896 The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard lib… Mcp Go Sdk 1.3.1+ Fix from $1,9502026-02-26 MEDIUM 6.5 CVE-2026-27735 Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to… Model Context Protocol Servers 2026.1.14+ Fix from $1,6002026-02-26 HIGH 7.5 CVE-2026-21864 Valkey-Bloom is a Rust based Valkey module which brings a Bloom Filter (Module) data type into the Valkey distributed key-value database. Prior to co… Valkey Bloom 1.0.1+ Fix from $1,9502026-02-24 HIGH 7.5 CVE-2026-27623 Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can… Valkey 9.0.3+ Fix from $1,9502026-02-23 HIGH 7.5 CVE-2026-21863 Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus… Valkey 7.2.12 / 8.0.7+ Fix from $1,9502026-02-23 HIGH 7.1 CVE-2025-67733 Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject … Valkey 7.2.12 / 8.0.7+ Fix from $1,9502026-02-23 HIGH 7.1 CVE-2026-25536 MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client respons… Mcp Typescript Sdk 1.26.0+ Fix from $1,9502026-02-04 HIGH 7.0 CVE-2025-10279 In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o77… Mlflow 3.4.0+ Fix from $1,9502026-02-02 HIGH 8.1 CVE-2025-14279 MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server… Mlflow 3.5.0+ Fix from $1,9502026-01-12 HIGH 7.5 CVE-2026-0621 Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTem… Mcp Typescript Sdk after 1.25.1 Fix from $1,9502026-01-05 CRITICAL 9.1 CVE-2025-68145EPSS 7% In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository… Model Context Protocol Servers 2025.12.18+ Fix from $2,3002025-12-17 HIGH 8.8 CVE-2025-68143EPSS 8% Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to… Model Context Protocol Servers 2025.9.25+ Fix from $1,9502025-12-17 HIGH 7.1 CVE-2025-68144EPSS 7% In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands… Model Context Protocol Servers 2025.12.17+ Fix from $1,9502025-12-17 HIGH 8.1 CVE-2025-66414 MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) T… Mcp Typescript Sdk 1.24.0+ Fix from $1,9502025-12-02 HIGH 8.1 CVE-2025-66416 The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context… Mcp Python Sdk 1.23.0+ Fix from $1,9502025-12-02 MEDIUM 5.3 CVE-2025-65105 Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --… Apptainer 1.4.5+ Fix from $1,6002025-12-02 CRITICAL 9.8 CVE-2025-11200 MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affecte… Mlflow after 2.21.0 Fix from $2,3002025-10-29 CRITICAL 9.8 CVE-2025-11201EPSS 27% MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute … Mlflow 2025-06-10+ Fix from $2,3002025-10-29 MEDIUM 5.5 CVE-2025-1474 In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security ri… Mlflow 2.19.0+ Fix from $1,6002025-03-20 HIGH 7.5 CVE-2025-0453EPSS 11% In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries… Mlflow No fix yet Fix from $1,9502025-03-20 HIGH 7.1 CVE-2025-1473 A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows … Mlflow 2.20.1+ Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-8859 A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly … Mlflow Patch available Fix from $1,9502025-03-20 MEDIUM 5.3 CVE-2024-6838 In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its… Mlflow No fix yet Fix from $1,6002025-03-20 HIGH 7.0 CVE-2024-27134 Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacke… Mlflow 2.16.0+ Fix from $1,9502024-11-25 MEDIUM 5.4 CVE-2024-3099 A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw c… Mlflow No fix yet Fix from $1,6002024-06-06 HIGH 7.5 CVE-2024-2928EPSS 22% A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vu… Mlflow 2.11.3+ Fix from $1,9502024-06-06 HIGH 8.8 CVE-2024-0520 A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS comm… Mlflow 2.9.0+ Fix from $1,9502024-06-06 HIGH 8.8 CVE-2024-37058 Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langch… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37059 Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorc… Mlflow No fix yet Fix from $1,9502024-06-04