Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.16% | — | Linuxfoundation Onnx | 21/8/2026 | 16/9/2026 | In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. A local attacker with write access to the directory where a victim serializes… | |
| Pendiente de análisis | Baja (3.3) | 0.17% | — | Onnx Open Neural Network ExchangeAI | 18/8/2026 | 18/9/2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer… | |
| Analizada | Media (5.5) | 0.19% | — | Linuxfoundation Onnx | 8/7/2026 | 13/7/2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_converter/adapters/upsample_6_7.h when processing an untrusted model… | |
| Aplazada | Baja (2.1) | 0.43% | — | OnnxruntimeAI | 4/7/2026 | 6/7/2026 | A weakness has been identified in onnx up to 1.21.x. This vulnerability affects the function convPoolShapeInference_opset19 of the file onnx/defs/nn/old.cc of the component onnxruntime. This manipulation causes out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been made available to… | |
| Aplazada | Baja (2) | 0.08% | — | Onnx-mlirAI | 5/6/2026 | 17/6/2026 | A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key of the file src/Runtime/python/torch_onnxmlir/src/torch_onnxmlir/backend.py of the component Placeholder Node Cache Handler. Such manipulation leads to use of weak hash. An attack has to be… | |
| Analizada | Media (5.5) | 0.19% | — | Linuxfoundation Onnx | 1/4/2026 | 17/6/2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external data loading allows reading files outside the model directory. This issue has been patched in version 1.21.0. | |
| Analizada | Media (5.5) | 0.17% | — | Linuxfoundation Onnx | 1/4/2026 | 17/6/2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code checks for symlinks to prevent path traversal, but completely misses hardlinks because a hardlink looks exactly like a regular file on the filesystem. This… | |
| Analizada | Alta (8.6) | 0.51% | — | Linuxfoundation Onnx | 1/4/2026 | 17/6/2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if the "keys" in the file… | |
| Modificada | Alta (8.7) | 0.62% | — | Linuxfoundation Onnx | 1/4/2026 | 15/7/2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0. | |
| Modificada | Crítica (9.1) | 0.31% | — | Linuxfoundation Onnx | 18/3/2026 | 15/7/2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the repository trust verification mechanism. While the function is designed to warn users when loading… | |
| Analizada | Alta (8.8) | 0.60% | — | Linuxfoundation Onnx | 22/7/2025 | 17/6/2026 | Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions. | |
| Analizada | Crítica (9.1) | 1.5% | — | Onnx | 20/3/2025 | 17/6/2026 | A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability can be exploited by an attacker to overwrite files in the user's… | |
| Analizada | Alta (8.7) | 0.37% | — | Connx ESP HR Management | 28/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script to be run in user's browser. After multiple attempts to contact the vendor we did not receive any answer. The finder… | |
| Modificada | Alta (8.8) | 1.2% | — | Linuxfoundation Onnx | 6/6/2024 | 17/6/2026 | A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability enables attackers to overwrite any file on the system, potentially leading to… | |
| Modificada | Crítica (9.1) | 0.59% | — | Linuxfoundation OnnxFedoraproject Fedora | 23/2/2024 | 17/6/2026 | Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy. | |
| Modificada | Alta (7.5) | 1.2% | — | Linuxfoundation OnnxFedoraproject Fedora | 23/2/2024 | 17/6/2026 | Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882. | |
| Modificada | Alta (7.5) | 1.6% | — | Linuxfoundation Onnx | 26/1/2023 | 17/6/2026 | Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd" | |
| Modificada | Media (6.5) | 0.77% | — | Softwareag Connx | 14/6/2022 | 9/7/2026 | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set. | |
| Modificada | Media (6.5) | 0.82% | — | Softwareag Connx | 14/6/2022 | 9/7/2026 | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set. | |
| Modificada | Crítica (9.8) | 1.3% | — | Connx ESP HR Management | 19/6/2018 | 17/6/2026 | SQL injection vulnerability in ConnX ESP HR Management 4.4.0 allows remote attackers to execute arbitrary SQL commands via the ctl00$cphMainContent$txtUserName parameter to frmLogin.aspx. | |
| Modificada | Alta (7.5) | 1.2% | — | Q2solutions Connx | 22/7/2010 | 16/6/2026 | SQL injection vulnerability in frmLoginPwdReminderPopup.aspx in Q2 Solutions ConnX 4.0.20080606 allows remote attackers to execute arbitrary SQL commands via the txtEmail parameter. |