Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.9) | 1.0% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function in vr.py. In uvr , if model_name contains the string… | |
| Analizada | Alta (8.9) | 1.0% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function in vr.py. In uvr , a new instance of AudioPre class is… | |
| Analizada | Alta (8.9) | 0.95% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_dir variable takes user input (e.g. a path to a model) and passes it to the change_info function in export.py, which uses it to load the model on that… | |
| Analizada | Alta (8.9) | 0.95% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_a and cpkt_b variables take user input (e.g. a path to a model) and pass it to the merge function in process_ckpt.py, which uses them to load the models… | |
| Analizada | Alta (8.9) | 0.96% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path0 variable takes user input (e.g. a path to a model) and passes it to the change_info function in process_ckpt.py, which uses it to load the model on… | |
| Analizada | Alta (8.9) | 0.96% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path2 variable takes user input (e.g. a path to a model) and passes it to the extract_small_model function in process_ckpt.py, which uses it to load the… | |
| Analizada | Alta (8.9) | 0.96% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path1 variable takes user input (e.g. a path to a model) and passes it to the show_info function in process_ckpt.py, which uses it to load the model on… | |
| Analizada | Alta (8.9) | 0.99% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to code injection. The ckpt_path2 variable takes user input (e.g. a path to a model) and passes it to change_info_ function, which opens and reads the file on the given path (except it… | |
| Analizada | Alta (8.9) | 2.2% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, among others, take user input and pass it to the click_train function, which concatenates them into a command that is run on the server. This… | |
| Analizada | Alta (8.9) | 2.4% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7 and f0method8 take user input and pass it into the extract_f0_feature function, which concatenates them into a command that is run on the… | |
| Analizada | Alta (8.9) | 2.2% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7, trainset_dir4 and sr2 take user input and pass it to the preprocess_dataset function, which concatenates them into a command that is run on… |