Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
466 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.70% | — | Tensoropera Fedml | 5/4/2026 | 24/7/2026 | A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtils.java of the component MQTT Message Handler. Performing a manipulation of the argument dataSet results in path traversal. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Alta (7.8) | 0.26% | — | Google TensorflowAIHdfgroup Hdf5AI | 20/2/2026 | 15/7/2026 | TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TensorFlow. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | |
| Aplazada | Media (5.9) | 0.25% | — | KerasAIGoogle TensorflowAI | 29/10/2025 | 17/6/2026 | The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability stems from the way the StringLookup layer is handled during model loading from a specially crafted… | |
| Aplazada | Media (4.7) | 0.14% | — | Teamviewer RemoteAITeamviewer TensorAI | 1/10/2025 | 17/6/2026 | Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by spoofing the update file path. This may… | |
| Analizada | Alta (7.5) | 0.21% | — | Google Tensorflow | 25/9/2025 | 17/6/2026 | An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D. | |
| Analizada | Media (6.5) | 0.17% | — | Google Tensorflow | 25/9/2025 | 17/6/2026 | TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application. | |
| Aplazada | Alta (7) | 0.17% | — | Teamviewer RemoteAITeamviewer TensorAI | 24/6/2025 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on Windows allows a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via leveraging the MSI rollback mechanism. The vulnerability only… | |
| Analizada | Alta (8.9) | 0.19% | — | Google Tensorflow Serving | 6/5/2025 | 17/6/2026 | Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash. | |
| Aplazada | Alta (8.8) | 0.28% | — | Nvidia Tensorrt-llmAI | 1/5/2025 | 17/6/2026 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access to the TRTLLM server. A successful exploit of this vulnerability may lead to code execution, information disclosure and data tampering. | |
| Modificada | Alta (7.5) | 0.43% | — | Google Tensorflow | 30/7/2024 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when not given a rank 2 tensor. The fix will be included in TensorFlow 2.13 and will also cherrypick this commit on TensorFlow 2.12. | |
| Analizada | Media (6.7) | 0.19% | — | Intel Optimization FOR Tensorflow | 14/2/2024 | 17/6/2026 | Improper buffer restrictions in Intel(R) Optimization for TensorFlow before version 2.13.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.16% | — | Intel Optimization FOR Tensorflow | 11/8/2023 | 17/6/2026 | Improper buffer restrictions in the Intel(R) Optimization for Tensorflow software before version 2.12 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.44% | — | Google Tensorflow | 27/3/2023 | 17/6/2026 | TensorFlow is an Open Source Machine Learning Framework. In versions prior to 2.11.1 a malicious invalid input crashes a tensorflow model (Check Failed) and can be used to trigger a denial of service attack. A proof of concept can be constructed with the `Convolution3DTranspose` function. This Convolution3DTranspose… | |
| Modificada | Alta (7.5) | 0.39% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an end-to-end open source platform for machine learning. Constructing a tflite model with a paramater `filter_input_channel` of less than 1 gives a FPE. This issue has been patched in version 2.12. TensorFlow will also cherrypick the fix commit on TensorFlow 2.11.1. | |
| Modificada | Alta (7.8) | 0.15% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool_v2` and `nn_ops.fractional_max_pool_v2` require the first and fourth elements of their parameter `pooling_ratio` to be equal to 1.0, as pooling on batch and channel dimensions is not supported. A… | |
| Modificada | Alta (7.5) | 0.39% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.ParallelConcat` segfaults with a nullptr dereference when given a parameter `shape` with rank that is not greater than zero. A fix is available in TensorFlow 2.12.0 and 2.11.1. | |
| Modificada | Alta (7.5) | 0.39% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.Bincount` segfaults when given a parameter `weights` that is neither the same shape as parameter `arr` nor a length-0 tensor. A fix is included in TensorFlow 2.12.0 and 2.11.1. | |
| Modificada | Alta (7.5) | 0.39% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an open source machine learning platform. Versions prior to 2.12.0 and 2.11.1 have a null pointer error in RandomShuffle with XLA enabled. A fix is included in TensorFlow 2.12.0 and 2.11.1. | |
| Modificada | Alta (7.5) | 0.39% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a Floating Point Exception in TensorListSplit with XLA. A fix is included in TensorFlow version 2.12.0 and version 2.11.1. | |
| Modificada | Alta (7.5) | 0.36% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an open source platform for machine learning. The function `tf.raw_ops.LookupTableImportV2` cannot handle scalars in the `values` parameter and gives an NPE. A fix is included in TensorFlow version 2.12.0 and version 2.11.1. | |
| Modificada | Alta (7.5) | 0.52% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an open source platform for machine learning. There is out-of-bounds access due to mismatched integer type sizes. A fix is included in TensorFlow version 2.12.0 and version 2.11.1. | |
| Modificada | Alta (7.5) | 0.39% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a null point error in QuantizedMatMulWithBiasAndDequantize with MKL enabled. A fix is included in TensorFlow version 2.12.0 and version 2.11.1. | |
| Modificada | Alta (7.5) | 0.39% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the stride and window size are not positive for `tf.raw_ops.AvgPoolGrad`, it can give a floating point exception. A fix is included in TensorFlow version 2.12.0 and version 2.11.1. | |
| Modificada | Crítica (9.8) | 0.84% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and will also cherrypick this commit on… | |
| Modificada | Alta (7.5) | 0.31% | — | Google Tensorflow | 25/3/2023 | 17/6/2026 | TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, integer overflow occurs when `2^31 <= num_frames * height * width * channels < 2^32`, for example Full HD screencast of at least 346 frames. A fix is included in TensorFlow version 2.12.0 and version 2.11.1. |