Zenml
This hub aggregates every CVE we track for Zenml, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
14
CVEs tracked
1
Critical
5
High
0
In CISA KEV
Severity distribution
MEDIUM6HIGH5LOW2CRITICAL1
Monthly trend
0
0
0
1
0
0
0
1
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
2024-082026-07
Latest CVEs
The 14 most recently published vulnerabilities affecting Zenml.
- CVE-2025-8406Path Traversal in zenml-io/zenml7.8
- CVE-2024-9340Denial of Service (DoS) via Multipart Boundary in zenml-io/zenml7.5
- CVE-2024-4311Lack of login attempt rate-limiting in zenml-io/zenml5.4
- CVE-2024-5062Reflected XSS through survey redirect parameter in zenml-io/zenml6.1
- CVE-2024-4680Insufficient Session Expiration in zenml-io/zenml8.8
- CVE-2024-2032Race Condition Vulnerability in zenml-io/zenml3.1
- CVE-2024-2035Improper Authorization in zenml-io/zenml6.5
- CVE-2024-2171Stored XSS in zenml-io/zenml4.8
- CVE-2024-2213Improper Authentication in zenml-io/zenml3.3
- CVE-2024-2383Clickjacking Vulnerability in zenml-io/zenml6.1
- CVE-2024-2083Directory Traversal in zenml-io/zenml9.9
- CVE-2024-2260Session Fixation Vulnerability in zenml-io/zenml4.2
- CVE-2024-28424zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arb...8.8
- CVE-2024-25723ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access o...8.8
Product normalization is registry-driven with AI assist and human review. How it works