HiddenLayer, Inc.
First CVE: Feb 5, 2024Active for: 2 years
53
CVEs Published
More CVEs Published than 59% of tracked CNAs
17.7
Avg CVEs / Year
More Avg CVEs / Year than 65% of tracked CNAs
8.4
Avg CVSS Score
Higher Avg CVSS Score than 94% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by HiddenLayer, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 5, 2024
2 years ago
Most Recent CVE
Jun 12, 2026
42 days ago
Top CVEs
All CVEs published by HiddenLayer, Inc. as a CNA, regardless of affected vendor or product.
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45829CRITICAL A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server b | May 18, 2026 | 10.0 | 52 | NO | NO |
CVE-2024-27322HIGH Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafte | Apr 29, 2024 | 8.8 | 40 | NO | NO |
CVE-2026-45833HIGH A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious | Jun 12, 2026 | 8.8 | 36 | NO | NO |
CVE-2025-62354CRITICAL Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands that are outside of those spec | Nov 26, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-62353CRITICAL A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of current projects on an end user’ | Oct 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-45832HIGH All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls | Jun 12, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-45830HIGH A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in an | Jun 12, 2026 | 8.8 | 33 | NO | NO |
CVE-2025-49655CRITICAL Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a maliciously uploaded Keras file co | Oct 17, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-8828HIGH A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any t | Jun 12, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-45831HIGH The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never che | Jun 12, 2026 | 8.8 | 31 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA53 CVEs
83%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (18.9%)
Network42 (79.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.9%)
Attack Complexity
Low48 (90.6%)
High5 (9.4%)
Unknown0 (0.0%)
User Interaction
None29 (54.7%)
Unknown0 (0.0%)
Required24 (45.3%)
Privileges Required
Low18 (34.0%)
High1 (1.9%)
None34 (64.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (53 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by HiddenLayer, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by HiddenLayer, Inc. as a CNA — matched by CVE ID, not by organization name.