Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zenml HIGH 7.8
CVE-2025-8406

ZenML version 0.83.1 is affected by a path traversal vulnerability in the `PathMaterializer` class. The `load` function uses `is_path_within_director…

Fix: 0.84.2+
Fix from $1,950 2025-10-05
Zenml HIGH 7.5
CVE-2024-9340

A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by …

Fix: 0.68.0+
Fix from $1,950 2025-03-20
Zenml MEDIUM 5.4
CVE-2024-4311

zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can …

Patch available
Fix from $1,600 2024-11-14
Zenml MEDIUM 6.1
CVE-2024-5062

A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutra…

Fix: 0.58.0+
Fix from $1,600 2024-06-30
Zenml HIGH 8.8
CVE-2024-4680

A vulnerability in zenml-io/zenml version 0.56.3 allows attackers to reuse old session credentials or session IDs due to insufficient session expirat…

No fix yet
Fix from $1,950 2024-06-08
Zenml MEDIUM 6.1
CVE-2024-2383

A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame…

Fix: 0.56.3+
Fix from $1,600 2024-06-06
Zenml MEDIUM 6.5
CVE-2024-2035

An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vuln…

Fix: 0.56.2+
Fix from $1,600 2024-06-06
Zenml CRITICAL 9.9
CVE-2024-2083EPSS 37%

A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit th…

Fix: 0.55.5+
Fix from $2,300 2024-04-16
Zenml HIGH 8.8
CVE-2024-28424

zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. Th…

No fix yet
Fix from $1,950 2024-03-14
Zenml HIGH 8.8
CVE-2024-25723EPSS 71%

ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_o…

Fix: 0.42.2 / 0.44.4+
Fix from $1,950 2024-02-27