lfprojects records
114 published records for vendor lfprojects.
Researcher profile
- Entered KEV
- 1 · 0.9%
- Weaponized
- 1 · 0.9%
- Pre-auth RCE
- 22
- With a fix record
- 82.5%
- Median publish → KEV
- 2 days
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')17
- CWE-29 Path Traversal: '\..\filename'11
- CWE-502 Deserialization of Untrusted Data9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-918 Server-Side Request Forgery (SSRF)5
- CWE-346 Origin Validation Error4
The weakness classes this vendor ships most often: where to look.
CWEAll records
114 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
70This week | CVE-2026-64849Weaponized | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)lfprojects · mlflow · CWE-918 | Critical9.3 | KEV | 9.8% | Aug 17, 2026 |
64This week | CVE-2025-49844Proof of concept | Redis Lua Use-After-Free may lead to remote code executionredis · redis · CWE-416 | Critical9.9 | — | 82.3% | Oct 3, 2025 |
60This week | CVE-2023-1177Proof of concept | Path Traversal: '\..\filename' in mlflow/mlflowlfprojects · mlflow · CWE-29 | Critical9.8 | — | 69.7% | Mar 24, 2023 |
60This week | CVE-2023-3765Proof of concept | Absolute Path Traversal in mlflow/mlflowlfprojects · mlflow · CWE-36 | Critical10.0 | — | 67.6% | Jul 18, 2023 |
57Plan | CVE-2023-6909Proof of concept | Path Traversal: '\..\filename' in mlflow/mlflowlfprojects · mlflow · CWE-29 | High7.5 | — | 89.7% | Dec 18, 2023 |
53Plan | CVE-2023-6018Proof of concept | MLflow Arbitrary File Writelfprojects · mlflow · CWE-78 | Critical9.8 | — | 47.9% | Nov 16, 2023 |
47Plan | CVE-2025-11201Proof of concept | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerabilitylfprojects · mlflow · CWE-22 | Critical9.8 | — | 27.0% | Oct 29, 2025 |
43Plan | CVE-2024-3848Proof of concept | Path Traversal Bypass in mlflow/mlflowlfprojects · mlflow · CWE-29 | High7.5 | — | 43.3% | May 16, 2024 |
41Plan | CVE-2023-43472Proof of concept | An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.lfprojects · mlflow | High7.5 | — | 36.6% | Dec 5, 2023 |
41Plan | CVE-2023-2780Proof of concept | Path Traversal: '\..\filename' in mlflow/mlflowlfprojects · mlflow · CWE-29 | Critical9.8 | — | 6.4% | May 17, 2023 |
41Plan | CVE-2025-15379No exploit | Command Injection in mlflow/mlflowlfprojects · mlflow · CWE-77 | Critical10.0 | — | 2.4% | Mar 30, 2026 |
40Plan | CVE-2026-0545Proof of concept | Missing Authentication for Critical Function in mlflow/mlflowlfprojects · mlflow · CWE-306 | Critical9.8 | — | 4.4% | Apr 3, 2026 |
40Plan | CVE-2023-6975No exploit | Path Traversal: '\..\filename'lfprojects · mlflow · CWE-29 | Critical9.8 | — | 2.0% | Dec 20, 2023 |
40Plan | CVE-2025-15036No exploit | Path Traversal Vulnerability in mlflow/mlflowlfprojects · mlflow · CWE-29 | Critical10.0 | — | 0.6% | Mar 29, 2026 |
39Monitor | CVE-2023-6974No exploit | Server-Side Request Forgery (SSRF)lfprojects · mlflow · CWE-918 | Critical9.8 | — | 1.5% | Dec 20, 2023 |
39Monitor | CVE-2025-11200No exploit | MLflow Weak Password Requirements Authentication Bypass Vulnerabilitylfprojects · mlflow · CWE-521 | Critical9.8 | — | 1.5% | Oct 29, 2025 |
39Monitor | CVE-2023-6014No exploit | MLflow Authentication Bypasslfprojects · mlflow · CWE-598 | Critical9.8 | — | 1.2% | Nov 16, 2023 |
38Monitor | CVE-2024-27132No exploit | Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.lfprojects · mlflow · CWE-79 | Critical9.6 | — | 0.9% | Feb 23, 2024 |
38Monitor | CVE-2024-27133No exploit | Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset.lfprojects · mlflow · CWE-79 | Critical9.6 | — | 0.7% | Feb 23, 2024 |
38Monitor | CVE-2026-2611No exploit | Improper Origin Validation in mlflow/mlflowlfprojects · mlflow · CWE-346 | Critical9.6 | — | 0.4% | May 19, 2026 |
37Monitor | CVE-2024-2928Proof of concept | Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflowlfprojects · mlflow · CWE-29 | High7.5 | — | 21.8% | Jun 6, 2024 |
37Monitor | CVE-2024-3573No exploit | Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflowlfprojects · mlflow · CWE-29 | Critical9.3 | — | 0.7% | Apr 15, 2024 |
36Monitor | CVE-2024-0520Proof of concept | Remote Code Execution due to Full Controlled File Write in mlflow/mlflowlfprojects · mlflow · CWE-22 | High8.8 | — | 2.4% | Jun 6, 2024 |
36Monitor | CVE-2025-15031No exploit | Path Traversal Vulnerability in mlflow/mlflowlfprojects · mlflow · CWE-22 | Critical9.1 | — | 0.9% | Mar 18, 2026 |
36Monitor | CVE-2026-2651No exploit | Missing Authorization Validation in mlflow/mlflowlfprojects · mlflow · CWE-862 | Critical9.0 | — | 0.5% | May 25, 2026 |
- CVE-2026-6484970This week
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
CriticalCVSS 9.3KEVWeaponizedEPSS 10%lfprojects · mlflowAug 17, 2026
- CVE-2025-4984464This week
Redis Lua Use-After-Free may lead to remote code execution
CriticalCVSS 9.9Proof of conceptEPSS 82%redis · redisOct 3, 2025
- CVE-2023-117760This week
Path Traversal: '\..\filename' in mlflow/mlflow
CriticalCVSS 9.8Proof of conceptEPSS 70%lfprojects · mlflowMar 24, 2023
- CVE-2023-376560This week
Absolute Path Traversal in mlflow/mlflow
CriticalCVSS 10.0Proof of conceptEPSS 68%lfprojects · mlflowJul 18, 2023
- CVE-2023-690957Plan
Path Traversal: '\..\filename' in mlflow/mlflow
HighCVSS 7.5Proof of conceptEPSS 90%lfprojects · mlflowDec 18, 2023
- CVE-2023-601853Plan
MLflow Arbitrary File Write
CriticalCVSS 9.8Proof of conceptEPSS 48%lfprojects · mlflowNov 16, 2023
- CVE-2025-1120147Plan
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 27%lfprojects · mlflowOct 29, 2025
- CVE-2024-384843Plan
Path Traversal Bypass in mlflow/mlflow
HighCVSS 7.5Proof of conceptEPSS 43%lfprojects · mlflowMay 16, 2024
- CVE-2023-4347241Plan
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.
HighCVSS 7.5Proof of conceptEPSS 37%lfprojects · mlflowDec 5, 2023
- CVE-2023-278041Plan
Path Traversal: '\..\filename' in mlflow/mlflow
CriticalCVSS 9.8Proof of conceptEPSS 6%lfprojects · mlflowMay 17, 2023
- CVE-2025-1537941Plan
Command Injection in mlflow/mlflow
CriticalCVSS 10.0No exploitEPSS 2%lfprojects · mlflowMar 30, 2026
- CVE-2026-054540Plan
Missing Authentication for Critical Function in mlflow/mlflow
CriticalCVSS 9.8Proof of conceptEPSS 4%lfprojects · mlflowApr 3, 2026
- CVE-2023-697540Plan
Path Traversal: '\..\filename'
CriticalCVSS 9.8No exploitEPSS 2%lfprojects · mlflowDec 20, 2023
- CVE-2025-1503640Plan
Path Traversal Vulnerability in mlflow/mlflow
CriticalCVSS 10.0No exploitEPSS 1%lfprojects · mlflowMar 29, 2026
- CVE-2023-697439Monitor
Server-Side Request Forgery (SSRF)
CriticalCVSS 9.8No exploitEPSS 2%lfprojects · mlflowDec 20, 2023
- CVE-2025-1120039Monitor
MLflow Weak Password Requirements Authentication Bypass Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%lfprojects · mlflowOct 29, 2025
- CVE-2023-601439Monitor
MLflow Authentication Bypass
CriticalCVSS 9.8No exploitEPSS 1%lfprojects · mlflowNov 16, 2023
- CVE-2024-2713238Monitor
Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.
CriticalCVSS 9.6No exploitEPSS 1%lfprojects · mlflowFeb 23, 2024
- CVE-2024-2713338Monitor
Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset.
CriticalCVSS 9.6No exploitEPSS 1%lfprojects · mlflowFeb 23, 2024
- CVE-2026-261138Monitor
Improper Origin Validation in mlflow/mlflow
CriticalCVSS 9.6No exploitEPSS 0%lfprojects · mlflowMay 19, 2026
- CVE-2024-292837Monitor
Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow
HighCVSS 7.5Proof of conceptEPSS 22%lfprojects · mlflowJun 6, 2024
- CVE-2024-357337Monitor
Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflow
CriticalCVSS 9.3No exploitEPSS 1%lfprojects · mlflowApr 15, 2024
- CVE-2024-052036Monitor
Remote Code Execution due to Full Controlled File Write in mlflow/mlflow
HighCVSS 8.8Proof of conceptEPSS 2%lfprojects · mlflowJun 6, 2024
- CVE-2025-1503136Monitor
Path Traversal Vulnerability in mlflow/mlflow
CriticalCVSS 9.1No exploitEPSS 1%lfprojects · mlflowMar 18, 2026
- CVE-2026-265136Monitor
Missing Authorization Validation in mlflow/mlflow
CriticalCVSS 9.0No exploitEPSS 1%lfprojects · mlflowMay 25, 2026