| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-33866 | Authorization Bypass in MLflow AJAX Endpoint | Mlflow | Mlflow | - | - | 2026-04-07 12:57:44 | Deep Dive |
| CVE-2026-33865 | Stored XSS via unsafe YAML parsing in MLflow | Mlflow | Mlflow | - | - | 2026-04-07 12:57:39 | Deep Dive |
| CVE-2026-0545 | Missing Authentication for Critical Function in mlflow/mlflow | mlflow | mlflow/mlflow | - | - | 2026-04-03 17:03:13 | Deep Dive |
| CVE-2026-0596 | Command Injection in mlflow/mlflow | mlflow | mlflow/mlflow | 中危 | - | 2026-03-31 14:25:28 | Deep Dive |
| CVE-2025-15379 | Command Injection in mlflow/mlflow | mlflow | mlflow/mlflow | 中危 | - | 2026-03-30 07:16:58 | Deep Dive |
| CVE-2025-15036 | Path Traversal Vulnerability in mlflow/mlflow | mlflow | mlflow/mlflow | 超危 | - | 2026-03-30 01:16:06 | Deep Dive |
| CVE-2025-15381 | Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow | mlflow | mlflow/mlflow | 中危 | - | 2026-03-27 16:17:30 | Deep Dive |
| CVE-2025-15031 | Path Traversal Vulnerability in mlflow/mlflow | mlflow | mlflow/mlflow | 高危 | - | 2026-03-18 22:06:47 | Deep Dive |
| CVE-2025-14287 | Command Injection in mlflow/mlflow | mlflow | mlflow/mlflow | 高危 | - | 2026-03-15 09:27:37 | Deep Dive |
| CVE-2026-2635 | MLflow Use of Default Password Authentication Bypass Vulnerability | MLflow | MLflow | - | - | 2026-02-20 22:25:03 | Deep Dive |
| CVE-2026-2033 | MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability | MLflow | MLflow | - | - | 2026-02-20 22:12:06 | Deep Dive |
| CVE-2025-10279 | Privilege Escalation in mlflow/mlflow | mlflow | mlflow/mlflow | - | - | 2026-02-02 10:36:23 | Deep Dive |
| CVE-2025-14279 | DNS Rebinding Vulnerability in mlflow/mlflow | mlflow | mlflow/mlflow | - | - | 2026-01-12 08:15:59 | Deep Dive |
| CVE-2025-11200 | MLflow Weak Password Requirements Authentication Bypass Vulnerability | MLflow | MLflow | - | - | 2025-10-29 19:42:04 | Deep Dive |
| CVE-2025-11201 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability | MLflow | MLflow | - | - | 2025-10-29 19:37:11 | Deep Dive |
| CVE-2025-52967 | MLflow 代码问题漏洞 | lfprojects | MLflow | Medium | 5.8 | 2025-06-23 00:00:00 | Deep Dive |
| CVE-2025-0453 | Denial of Service through Batched Queries in GraphQL in mlflow/mlflow | mlflow | mlflow/mlflow | 中危 | - | 2025-03-20 10:11:03 | Deep Dive |
| CVE-2025-1473 | CSRF in mlflow/mlflow | mlflow | mlflow/mlflow | 中危 | - | 2025-03-20 10:10:21 | Deep Dive |
| CVE-2025-1474 | Weak Password Requirements in mlflow/mlflow | mlflow | mlflow/mlflow | 中危 | - | 2025-03-20 10:10:21 | Deep Dive |
| CVE-2024-8859 | Path Traversal in mlflow/mlflow | mlflow | mlflow/mlflow | 高危 | - | 2025-03-20 10:09:53 | Deep Dive |