Every published CVE from the last 120 days with CVSS score, vendor and product, cross-referenced against CISA's Known Exploited Vulnerabilities catalog. 10 added to KEV in the last 7 days.
| CVE | CVSS | Severity | Vendor / product | Summary | Published |
|---|---|---|---|---|---|
| CVE-2026-2611 | 9.6 | critical | lfprojects / mlflow | In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoi | 109d ago |
| CVE-2026-64849exploited | 9.3 | critical | lfprojects / mlflow | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. | 19d ago |
| CVE-2025-15031 | 9.1 | critical | lfprojects / mlflow | A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of | 171d ago |
| CVE-2026-2651 | 9 | critical | lfprojects / mlflow | A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints whe | 103d ago |
Sources: NIST National Vulnerability Database (descriptions, CVSS, CPE) and CISA Known Exploited Vulnerabilities catalog (exploitation status). Both are United States government works in the public domain. Data refreshes daily; KEV hourly.