Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
74 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.80% | — | Pytorch TorchAINebuly OptimateAI | 12/5/2026 | 17/6/2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When loading a model state dictionary from a state_dict.pt file via torch.load(), the function does not enable… | |
| Aplazada | Crítica (9.8) | 0.88% | — | Pytorch TorchAI | 12/5/2026 | 17/6/2026 | The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The script uses torch.load() to process PyTorch checkpoint files (.pt) without enabling the security-restrictive… | |
| Aplazada | Alta (7.3) | 0.36% | — | CosyvoiceAIPytorchAI | 11/5/2026 | 17/6/2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads PyTorch checkpoint files (epoch_*.pt) for model averaging using torch.load() without enabling the weights_only=True… | |
| Pendiente de análisis | Crítica (9) | 0.58% | — | Nvidia ApexAIPytorchAI | 24/3/2026 | 17/6/2026 | NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions earlier than 2.6. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of… | |
| Analizada | Baja (1.9) | 0.40% | — | Linuxfoundation Pytorch | 22/3/2026 | 17/6/2026 | A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the… | |
| Modificada | Alta (8.8) | 0.81% | — | Linuxfoundation Pytorch | 27/1/2026 | 15/7/2026 | PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary… | |
| Modificada | Baja (3.3) | 0.12% | — | Linuxfoundation Pytorch | 12/11/2025 | 5/7/2026 | An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS). | |
| Analizada | Alta (7.5) | 0.41% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor. | |
| Analizada | Alta (7.5) | 0.45% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS). | |
| Analizada | Alta (7.5) | 0.41% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS). | |
| Analizada | Media (5.3) | 0.32% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long(). | |
| Analizada | Alta (7.5) | 0.41% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS). | |
| Analizada | Alta (7.5) | 0.42% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together. | |
| Analizada | Alta (7.5) | 0.42% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation. | |
| Analizada | Media (5.3) | 0.42% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True. | |
| Analizada | Media (5.3) | 0.45% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument. | |
| Analizada | Media (5.3) | 0.39% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results. | |
| Analizada | Media (5.3) | 0.36% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error. | |
| Analizada | Media (5.3) | 0.40% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results. | |
| Aplazada | Media (4.8) | 0.20% | — | Vita-mllm Freeze-omniAIPytorch TorchAI | 15/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.load of the file models/utils.py. The manipulation of the argument path leads to deserialization. It is possible to launch the attack on the local host. | |
| Aplazada | Media (4.8) | 0.19% | — | PytorchAI | 5/5/2025 | 17/6/2026 | A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.3) | 2.2% | — | Linuxfoundation Pytorch | 18/4/2025 | 17/6/2026 | PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue… | |
| Analizada | Media (4.8) | 0.33% | — | Linuxfoundation Pytorch | 16/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may… | |
| Analizada | Media (4.8) | 0.26% | — | Linuxfoundation Pytorch | 3/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been… | |
| Analizada | Media (4.8) | 0.27% | — | Linuxfoundation Pytorch | 2/4/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. |