Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.94% | — | AxolotlAIHuggingface TransformersAI | 5/9/2026 | 23/9/2026 | Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as… | |
| Pendiente de análisis | Alta (7.8) | 0.10% | — | Huggingface TransformersAI | 1/9/2026 | 23/9/2026 | A vulnerability in Hugging Face Transformers (versions 4.57.0 to 5.16.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches and caches a remote module file before performing the required trust_remote_code consent… | |
| Pendiente de análisis | Media (6.8) | 0.29% | — | Huggingface TransformersAI | 17/8/2026 | 24/9/2026 | Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Huggingface TransformersAIHuggingface IdeficsAIHuggingface FlorenceAIHuggingface GemmaAI+2 | 2/8/2026 | 3/9/2026 | A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames… | |
| Aplazada | Crítica (9.3) | 0.91% | — | Sentence-transformersAI | 31/7/2026 | 9/9/2026 | sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or os.path.exists(model_name_or_path)' clause… | |
| Pendiente de análisis | Media (4.3) | 0.38% | — | Nvidia Transformers4recAI | 21/7/2026 | 21/7/2026 | NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Aplazada | Crítica (9.3) | 1.1% | — | Kvcache-ai KtransformersAI | 20/7/2026 | 23/7/2026 | ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious… | |
| Modificada | Crítica (9.6) | 0.94% | — | Huggingface Transformers | 3/6/2026 | 28/8/2026 | A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by… | |
| Aplazada | Crítica (9.3) | 1.3% | — | OpenmedAIHuggingface TransformersAI | 2/6/2026 | 28/8/2026 | OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied model_name parameter, allowing a value such as attacker/foo-privacy-filter-bar to route through a path that loads Hugging… | |
| Analizada | Alta (7.8) | 0.42% | — | Nvidia Transformers4rec | 26/5/2026 | 24/7/2026 | NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.60% | — | Huggingface Transformers | 24/5/2026 | 23/7/2026 | A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub… | |
| Aplazada | Media (6.3) | 0.42% | — | Huggingface TransformersAILmsys SglangAI | 2/5/2026 | 17/6/2026 | A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation of the argument trust_remote_code with the input False as part of Boolean results in… | |
| Analizada | Crítica (9.3) | 1.0% | — | Kvcache-ai Ktransformers | 23/4/2026 | 14/7/2026 | KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can send a crafted… | |
| Analizada | Alta (7.8) | 0.38% | — | Huggingface Transformers | 7/4/2026 | 17/6/2026 | A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library… | |
| Aplazada | Alta (7.8) | 0.23% | — | Nvidia Merlin Transformers4recAI | 20/1/2026 | 17/6/2026 | NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Analizada | Alta (7.8) | 0.33% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.37% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that… | |
| Analizada | Alta (7.8) | 0.34% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a… | |
| Analizada | Alta (7.8) | 0.34% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a… | |
| Analizada | Alta (7.8) | 0.34% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a… | |
| Analizada | Alta (7.8) | 0.33% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must… | |
| Analizada | Alta (7.8) | 0.33% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the… | |
| Analizada | Alta (7.8) | 0.36% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target… | |
| Aplazada | Alta (8.8) | 0.66% | — | Nvidia Merlin Transformers4recAI | 9/12/2025 | 17/6/2026 | NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering. | |
| Analizada | Alta (7.5) | 0.51% | — | Huggingface Transformers | 23/9/2025 | 17/6/2026 | The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability arises from the _do_use_weight_decay method, which processes user-controlled regular expressions in the include_in_weight_decay and… |