Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
114 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.41% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS). | |
| Analizada | Media (5.3) | 0.32% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long(). | |
| Analizada | Alta (7.5) | 0.41% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS). | |
| Analizada | Alta (7.5) | 0.42% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together. | |
| Analizada | Alta (7.5) | 0.42% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation. | |
| Analizada | Media (5.3) | 0.42% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True. | |
| Analizada | Media (5.3) | 0.45% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument. | |
| Analizada | Media (5.3) | 0.39% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results. | |
| Analizada | Media (5.3) | 0.36% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error. | |
| Analizada | Media (5.3) | 0.40% | — | Linuxfoundation Pytorch | 25/9/2025 | 17/6/2026 | In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results. | |
| Aplazada | Crítica (9.8) | 0.61% | — | Meta ExecutorchAI | 8/8/2025 | 17/6/2026 | An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 8f062d3f661e20bb19b24b767b9a9a46e8359f2b. | |
| Aplazada | Crítica (9.8) | 0.69% | — | Meta ExecutorchAI | 7/8/2025 | 17/6/2026 | A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit cea9b23aa8ff78aff92829a466da97461cc7930c. | |
| Aplazada | Crítica (9.8) | 0.62% | — | Meta ExecutorchAI | 7/8/2025 | 17/6/2026 | An out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit b6b7a16df5e7852d976d8c34c8a7e9a1b6f7d005. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Meta ExecutorchAI | 7/8/2025 | 17/6/2026 | A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit ede82493dae6d2d43f8c424e7be4721abe5242be | |
| Aplazada | Crítica (9.8) | 0.62% | — | Meta ExecutorchAI | 7/8/2025 | 17/6/2026 | An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their allocated memory area, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 0830af8207240df8d7f35b984cdf8bc35d74fa73. | |
| Aplazada | Crítica (9.8) | 0.62% | — | Meta ExecutorchAI | 7/8/2025 | 17/6/2026 | An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit d158236b1dc84539c1b16843bc74054c9dcba006. | |
| Aplazada | Alta (8.1) | 0.39% | — | Meta ExecutorchAI | 11/7/2025 | 17/6/2026 | A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f | |
| Aplazada | Media (4.8) | 0.20% | — | Vita-mllm Freeze-omniAIPytorch TorchAI | 15/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.load of the file models/utils.py. The manipulation of the argument path leads to deserialization. It is possible to launch the attack on the local host. | |
| Aplazada | Media (4.8) | 0.19% | — | PytorchAI | 5/5/2025 | 17/6/2026 | A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.3) | 2.2% | 💥 PoC | Linuxfoundation Pytorch | 18/4/2025 | 17/6/2026 | PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue… | |
| Analizada | Media (4.8) | 0.33% | — | Linuxfoundation Pytorch | 16/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may… | |
| Analizada | Media (4.8) | 0.26% | — | Linuxfoundation Pytorch | 3/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been… | |
| Analizada | Media (4.8) | 0.27% | — | Linuxfoundation Pytorch | 2/4/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (4.8) | 0.20% | — | Linuxfoundation Pytorch | 31/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (4.8) | 0.20% | — | Linuxfoundation Pytorch | 31/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. |