Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

86 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Lfprojects Mlflow16/11/202317/6/2026
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
ModificadaCrítica (9.8)48%💥 ExploitLfprojects Mlflow16/11/202317/6/2026
An attacker can overwrite any file on the server hosting MLflow without any authentication.
ModificadaAlta (7.5)4.4%—Lfprojects Mlflow16/11/202317/6/2026
MLflow allowed arbitrary files to be PUT onto the server.
ModificadaAlta (7.8)1.3%—Lfprojects Mlflow1/8/202317/6/2026
OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
ModificadaCrítica (10)68%💥 ExploitLfprojects Mlflow19/7/202317/6/2026
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
ModificadaCrítica (9.8)6.4%💥 ExploitLfprojects Mlflow17/5/202317/6/2026
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.
ModificadaAlta (7.5)1.0%—Lfprojects Mlflow11/5/202317/6/2026
A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on the server via the path parameter.
ModificadaAlta (7.5)4.2%💥 ExploitLfprojects Mlflow28/4/202317/6/2026
Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.
ModificadaCrítica (9.8)70%💥 ExploitLfprojects Mlflow24/3/202317/6/2026
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.
ModificadaBaja (3.3)0.58%—Lfprojects Mlflow24/3/202317/6/2026
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.
ModificadaAlta (7.5)1.6%—Lfprojects Mlflow23/2/202217/6/2026
Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.
Orbitaley — Vulnerabilidades