Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lfprojects

First CVE: Feb 23, 2022Active for: 4 yearsTotal CVEs: 114
67.4
VTI Score
TOP TARGET

The Linux Foundation Projects ecosystem encompasses a diverse portfolio of widely deployed open-source software spanning machine learning (MLflow), data systems (Valkey), AI infrastructure (Model Context Protocol servers and implementations), and container runtimes (Apptainer), positioning it as a foundational layer across research, cloud-native, and enterprise deployments. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency toward public exploit availability, reflecting the sensitivity of the software supply chain and the appeal of foundational infrastructure to weaponization efforts. The exposure recurs across these distinct product lines through weakness classes including path-traversal variants, deserialization of untrusted data, and cross-site scripting, patterns characteristic of systems that parse external inputs, load serialized state, or expose web interfaces. Defenders should monitor this vendor's releases across its disparate products closely, as patches to foundational tools like Valkey or Apptainer can have broad downstream impact on containerized and ML workloads. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
114
Total CVEs
More Total CVEs than 99% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lfprojects over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 23, 2022
4 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Products(18 total)

Top CVEs

Signals from CVEs in this vendor scope (114 CVEs).

114 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-49844CRITICAL
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garb
Oct 3, 20259.983NONO
CVE-2023-6909HIGH
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
Dec 18, 20237.579NOYES
CVE-2023-1177CRITICAL
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.
Mar 24, 20239.879NOYES
CVE-2023-3765CRITICAL
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
Jul 19, 202310.077NOYES
CVE-2023-6018CRITICAL
An attacker can overwrite any file on the server hosting MLflow without any authentication.
Nov 16, 20239.867NOYES
CVE-2024-3848HIGH
A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the applicat
May 16, 20247.555NOYES
CVE-2026-0545CRITICAL
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerabili
Apr 3, 20269.850NOYES
CVE-2025-11201CRITICAL
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst
Oct 29, 20259.850NONO
CVE-2023-43472HIGH
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.
Dec 5, 20237.547NOYES
CVE-2023-2780CRITICAL
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.
May 17, 20239.846NOYES
View all 114 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products114 CVEs
18%
61%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local11 (9.6%)
Network102 (89.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.9%)
Attack Complexity
Low108 (94.7%)
High6 (5.3%)
Unknown0 (0.0%)
User Interaction
None76 (66.7%)
Unknown0 (0.0%)
Required38 (33.3%)
Privileges Required
Low33 (28.9%)
High1 (0.9%)
None80 (70.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (114 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
16 CVEs
14.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lfprojects.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lfprojects — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lfprojects's Products

View all 9 CNAs →

Top CWEs