Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.3% | — | Paddlepaddle | 26/7/2023 | 17/6/2026 | PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system. | |
| Modificada | Alta (7.5) | 0.74% | — | Paddlepaddle | 26/7/2023 | 17/6/2026 | FPE in paddle.trace in PaddlePaddle before 2.5.0. This flaw can cause a runtime crash and a denial of service. | |
| Modificada | Crítica (9.8) | 0.76% | — | Paddlepaddle | 26/7/2023 | 17/6/2026 | Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible. | |
| Modificada | Alta (7.5) | 0.66% | — | Paddlepaddle | 26/7/2023 | 17/6/2026 | Null pointer dereference in paddle.flip in PaddlePaddle before 2.5.0. This resulted in a runtime crash and denial of service. | |
| Modificada | Crítica (9.8) | 0.77% | — | Paddlepaddle | 26/7/2023 | 17/6/2026 | Use after free in paddle.diagonal in PaddlePaddle before 2.5.0. This resulted in a potentially exploitable condition. | |
| Modificada | Crítica (9.8) | 1.1% | — | Paddlepaddle | 7/12/2022 | 17/6/2026 | Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution. | |
| Modificada | Crítica (9.1) | 0.68% | — | Paddlepaddle | 7/12/2022 | 17/6/2026 | Out-of-bounds read in gather_tree in PaddlePaddle before 2.4. | |
| Modificada | Crítica (9.8) | 1.4% | — | Paddlepaddle | 26/11/2022 | 17/6/2026 | In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution. | |
| Modificada | Crítica (9.3) | 1.3% | — | Paddlepaddle Anakin | 11/7/2022 | 17/6/2026 | The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |