HiddenLayer
CVE Numbering Authority
Latest CVE published
Overview
HiddenLayer is a CVE Numbering Authority that has published 46 CVE records since 2024. It is currently classified as active, with 40 CVEs published in the last two years. Its CVE data quality is graded A (100% overall completeness).
Among the 370 CNAs tracked here, HiddenLayer ranks #174 by CVE volume and reports more complete records than 60% of all CNAs.
Data quality report card
How complete and consistent HiddenLayer's CVE records are, scored across vendor, product, CVSS, and CWE coverage.
A CVE record only requires a description to be published. “Completeness” measures how often HiddenLayer also fills in the optional — but extremely useful — fields that make a vulnerability actually actionable: the affected vendor and product, a CVSS severity score, and a CWE weakness type. A higher score means more of this CNA’s CVEs include those details, so defenders spend less time enriching records by hand.
Report card grade
100%
Overall score
What these scores mean
- Vendor completeness
- The share of this CNA's CVEs that name an affected vendor.
- Product completeness
- The share that name a specific affected product.
- CVSS completeness
- The share that include a CVSS severity score.
- CWE completeness
- The share mapped to a CWE weakness type.
- Update rate
- How often this CNA revises CVE records after first publishing them.
- Vendor diversity
- How many distinct vendors this CNA publishes CVEs for.
Severity and exploitation
How the CVSS severity of HiddenLayer's published CVEs breaks down, and how many are known to be exploited in the wild.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of HiddenLayer's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Common weakness types
The CWE weakness categories HiddenLayer most often assigns to its CVEs. Follow any weakness to its full explanation.
- CWE-502Deserialization of Untrusted Data21 CVEs
- CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')9 CVEs
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6 CVEs
- CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4 CVEs
- CWE-639Authorization Bypass Through User-Controlled Key3 CVEs
- CWE-94Improper Control of Generation of Code ('Code Injection')3 CVEs
- CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2 CVEs
- CWE-863Incorrect Authorization1 CVE
Publishing activity by year
How many CVEs HiddenLayer has published each year.
Top vendors
The vendors HiddenLayer publishes the most CVEs for.
- mindsdb11 CVEs
- MLflow10 CVEs
- lfprojects10 CVEs
- Allegro.AI6 CVEs
- clear6 CVEs
- Chroma6 CVEs
- chroma-core5 CVEs
- Red Hat4 CVEs
Top products
The products HiddenLayer publishes the most CVEs for.
- mindsdb11 CVEs
- MLflow10 CVEs
- ChromaDB6 CVEs
- ClearML6 CVEs
- Red Hat Enterprise Linux AI (RHEL AI) 34 CVEs
- chroma4 CVEs
- BackendAI3 CVEs
- backend.ai3 CVEs
Latest CVEs
The most recent CVEs assigned by HiddenLayer.
- CVE-2026-79720CWE-79Medium · CVSS 6.8EPSS 0.2%2026-08-27
- CVE-2026-79719CWE-79Medium · CVSS 6.8EPSS 0.2%2026-08-27
- CVE-2026-79718CWE-79Medium · CVSS 6.8EPSS 0.2%2026-08-27
- CVE-2026-45833CWE-94Critical · CVSS 9.4EPSS 0.3%2026-06-12
- CVE-2026-45832CWE-639High · CVSS 8.8EPSS 0.3%2026-06-12
- CVE-2026-45831CWE-863High · CVSS 8.8EPSS 0.2%2026-06-12
- CVE-2026-8828CWE-639High · CVSS 8.8EPSS 0.3%2026-06-12
- CVE-2026-45830CWE-639High · CVSS 8.8EPSS 0.3%2026-06-12
- CVE-2026-45829CWE-94Critical · CVSS 10.0EPSS 12.4%2026-05-18
- CVE-2026-3071CWE-502High · CVSS 8.4EPSS 0.2%2026-02-26
- CVE-2025-62354CWE-78Critical · CVSS 9.8EPSS 1.4%2025-11-26
- CVE-2025-62356CWE-22High · CVSS 7.5EPSS 0.6%2025-10-17
Track new HiddenLayer CVEs as they are published and get AI-written analysis and remediation guidance.
Monitor HiddenLayer CVEsOther CNAs
Compare data quality across other CVE Numbering Authorities.
Frequently asked questions
Common questions about the HiddenLayer CNA.
- What is the HiddenLayer CNA?
- HiddenLayer is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 46 CVE records since 2024.
- How many CVEs has HiddenLayer published?
- HiddenLayer has published 46 CVE records, including 40 in the last two years.
- What is HiddenLayer's CVE data quality grade?
- RadicalNotion.AI grades HiddenLayer's CVE data quality as A, with an overall completeness score of 100%. This reflects how consistently its CVE records include vendor (100%), product (100%), CVSS (100%), and CWE (100%) information.
- What products does HiddenLayer publish CVEs for?
- HiddenLayer most frequently publishes CVEs for mindsdb, MLflow, ChromaDB, ClearML, Red Hat Enterprise Linux AI (RHEL AI) 3.
- Which vendors does HiddenLayer cover?
- HiddenLayer publishes CVEs across 16 distinct vendors, most often mindsdb, MLflow, lfprojects, Allegro.AI, clear.
- Is HiddenLayer actively publishing CVEs?
- HiddenLayer is currently active, based on 40 CVEs in the last two years.
- What is the average severity of HiddenLayer's CVEs?
- The average CVSS base score across HiddenLayer's scored CVEs is 8.3.
- How many critical CVEs has HiddenLayer published?
- HiddenLayer has published 10 critical-severity CVEs and 42 high-severity CVEs.
- Are any of HiddenLayer's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- No. None of HiddenLayer's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the most common weakness types in HiddenLayer's CVEs?
- HiddenLayer's CVEs most often map to these CWE weakness types: CWE-502 (Deserialization of Untrusted Data), CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
- How does HiddenLayer rank among CNAs?
- By total CVE volume, HiddenLayer ranks #174 of 370 CNAs, and it reports more complete CVE records than 60% of all CNAs.
References
- Official CVE.org list of CNA partners (opens in a new tab)
- Learn: What is a CNA?
- CWE directory: the weakness types this CNA maps its CVEs to
CNA report-card grades are computed by RadicalNotion.AI from published CVE records. CVE data is sourced from the CVE Program.
Track HiddenLayer CVEs
Monitor new vulnerabilities as this CNA publishes them, with AI-written analysis and remediation guidance.