Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.38% | — | Huggingface Transformers | 7/4/2026 | 17/6/2026 | A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library… | |
| Analizada | Baja (2.1) | 0.73% | — | Huggingface Smolagents | 27/3/2026 | 17/6/2026 | A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the file src/smolagents/local_python_executor.py of the component Incomplete Fix CVE-2025-9959. This manipulation causes code injection. It is possible to initiate the… | |
| Analizada | Baja (2.1) | 0.55% | — | Huggingface Smolagents | 18/2/2026 | 17/6/2026 | A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public… | |
| Aplazada | Alta (7.5) | 30% | — | Huggingface Text-generation-inferenceAI | 2/2/2026 | 17/6/2026 | A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The issue arises when the router scans inputs for Markdown image links and performs a blocking HTTP GET request, reading the… | |
| Aplazada | Crítica (10) | 1.1% | — | Huggingface SmolagentsAI | 23/12/2025 | 17/6/2026 | Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face smolagents. Authentication is not required to exploit this vulnerability. The specific… | |
| Analizada | Alta (7.8) | 0.33% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.37% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that… | |
| Analizada | Alta (7.8) | 0.34% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a… | |
| Analizada | Alta (7.8) | 0.34% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a… | |
| Analizada | Alta (7.8) | 0.34% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a… | |
| Aplazada | Alta (7.8) | 0.37% | — | Huggingface AccelerateAI | 23/12/2025 | 17/6/2026 | Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Accelerate. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7.8) | 0.33% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must… | |
| Aplazada | Alta (7.8) | 0.37% | — | Cogview4AIHuggingface DiffusersAI | 23/12/2025 | 17/6/2026 | Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Diffusers. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.33% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the… | |
| Analizada | Alta (7.8) | 0.36% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Media (5.4) | 0.28% | — | Huggingface Smolagents | 22/10/2025 | 17/6/2026 | Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function located in src/smolagents/vision_web_browser.py. The function constructs an XPath query by directly concatenating user-supplied input into the XPath expression without proper sanitization or escaping.… | |
| Analizada | Alta (7.5) | 0.51% | — | Huggingface Transformers | 23/9/2025 | 17/6/2026 | The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability arises from the _do_use_weight_decay method, which processes user-controlled regular expressions in the include_in_weight_decay and… | |
| Aplazada | Media (5.3) | 0.29% | — | Huggingface LerobotAI | 22/9/2025 | 17/6/2026 | A vulnerability was identified in huggingface LeRobot up to 0.3.3. Affected by this vulnerability is an unknown functionality of the file lerobot/common/robot_devices/robots/lekiwi_remote.py of the component ZeroMQ Socket Handler. The manipulation leads to missing authentication. The attack can only be initiated… | |
| Analizada | Media (5.3) | 0.38% | — | Huggingface Transformers | 14/9/2025 | 30/9/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer` class. This vulnerability affects versions up to 4.52.4 and is fixed in version 4.53.0. The issue arises from the… | |
| Analizada | Alta (7.5) | 0.53% | — | Huggingface Transformers | 12/9/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version 4.53.0. The issue arises from inefficient… | |
| Aplazada | Alta (7.6) | 0.31% | — | Huggingface SmolagentsAI | 3/9/2025 | 25/9/2026 | Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to create malicious code. | |
| Analizada | Media (5.3) | 0.40% | — | Huggingface Transformers | 6/8/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting TensorFlow weight names to PyTorch format, uses a regex pattern `/[^/]*___([^/]*)/` that can… | |
| Analizada | Crítica (10) | 25% | — | Huggingface Smolagents | 27/7/2025 | 17/6/2026 | A sandbox escape vulnerability was identified in huggingface/smolagents version 1.14.0, allowing attackers to bypass the restricted execution environment and achieve remote code execution (RCE). The vulnerability stems from the local_python_executor.py module, which inadequately restricts Python code execution despite… | |
| Analizada | Media (5.3) | 0.46% | — | Huggingface Transformers | 11/7/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability affects versions 4.50.3 and earlier, and is fixed in version 4.52.1. The issue arises from the regex pattern… | |
| Analizada | Baja (3.5) | 0.38% | — | Huggingface Transformers | 7/7/2025 | 17/6/2026 | Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackers to craft URLs that… |