Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▲ 67 respecto a la semana anterior
Críticas / altas1456▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
114 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.45% | — | DLR Stable-baselines3AIPytorchAI | 20/9/2026 | 21/9/2026 | A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Alta (7.7) | 0.69% | — | Kedro DatasetsAIPytorchAI | 16/9/2026 | 30/9/2026 | Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-datasets loads .pt model files with torch.load without enforcing weights_only=True, and user-supplied load_args are silently dropped. On PyTorch versions earlier than 2.6, a… | |
| Aplazada | Media (4.3) | 0.34% | — | DjangoAITorchbox WagtailAI | 24/8/2026 | 9/9/2026 | Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve… | |
| Pendiente de análisis | Alta (7.8) | 0.45% | — | Huggingface Pytorch Image ModelsAI | 20/8/2026 | 31/8/2026 | Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the… | |
| En análisis | Media (5.4) | 0.16% | — | Intel LLM Library FOR PytorchAI | 11/8/2026 | 12/8/2026 | Protection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local… | |
| Analizada | Media (4.6) | 0.26% | — | Intel Extension FOR Pytorch | 11/8/2026 | 30/9/2026 | Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Media (5.4) | 0.12% | — | Intel Oneccl Bindings FOR Pytorch | 11/8/2026 | 1/10/2026 | Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Alta (8.8) | 0.50% | — | Pytorch TorchAIHuggingface PeftAI | 5/8/2026 | 26/8/2026 | Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load on config-specified cache/covariance files without weights_only=True, bypassing peft's own safe-loading wrapper used elsewhere in the codebase. | |
| Analizada | Alta (7.1) | 0.45% | — | Linuxfoundation Torchvision | 23/7/2026 | 17/9/2026 | PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose… | |
| Pendiente de análisis | Alta (7.8) | 0.39% | — | PytorchAIKerasAI | 19/7/2026 | 23/7/2026 | A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)` without requiring an explicit unsafe opt-in, such as a… | |
| Analizada | Alta (8.4) | 0.63% | — | Lightningai Pytorch Lightning | 15/7/2026 | 6/8/2026 | PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True… | |
| Aplazada | Baja (1.9) | 0.32% | — | Yashbhalgat Hashnerf-pytorchAI | 13/7/2026 | 13/7/2026 | A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to deserialization. The attack must be… | |
| Aplazada | Alta (7.6) | 0.56% | — | Pytorch PicklescanAIPytorch TorchAI | 4/7/2026 | 30/9/2026 | picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. Remote attackers can embed undetected malicious code in pickle files that executes during deserialization, enabling remote code… | |
| Aplazada | Alta (7.6) | 0.38% | — | Pytorch TorchAIMmaitre314 PicklescanAI | 4/7/2026 | 30/9/2026 | picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. Attackers can embed undetected code in pickle files that executes remote code when loaded by victims. | |
| Aplazada | Alta (7.6) | 0.38% | — | Pytorch TorchAIMmaitre314 PicklescanAI | 4/7/2026 | 30/9/2026 | picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that evades picklescan detection and executes arbitrary commands when loaded. | |
| Aplazada | Alta (7.6) | 0.54% | — | Pytorch TorchAIMmaitre314 PicklescanAI | 4/7/2026 | 30/9/2026 | picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code execution. | |
| Aplazada | Alta (7.6) | 0.54% | — | Python IdlelibAIPytorchAIMmaitre314 PicklescanAI | 4/7/2026 | 30/9/2026 | picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks. | |
| Analizada | Alta (7.3) | 0.36% | — | Torchbox Wagtail | 1/7/2026 | 6/7/2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS) vulnerability exists on the dynamic image URL generator view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin… | |
| Analizada | Media (4.3) | 0.27% | — | Torchbox Wagtail | 1/7/2026 | 2/7/2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for. This issue has been fixed in versions 7.0.8, 7.3.3, and… | |
| Analizada | Media (6.5) | 0.34% | — | Torchbox Wagtail | 1/7/2026 | 2/7/2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any image. The existing data of the image object itself is not exposed. The… | |
| Analizada | Baja (2.7) | 0.37% | — | Torchbox Wagtail | 1/7/2026 | 2/7/2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger expensive rendition processing with purposefully crafted filter specs resulting in potentially service degradation. The vulnerability is not exploitable by an… | |
| Analizada | Media (4.3) | 0.27% | — | Torchbox Wagtail | 1/7/2026 | 2/7/2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose permission. A user with access to the Wagtail admin could see the filename and… | |
| Aplazada | Alta (7.6) | 0.45% | — | Pytorch TorchAIMmaitre314 PicklescanAI | 30/6/2026 | 30/9/2026 | picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims. | |
| Aplazada | Alta (7.6) | 0.48% | — | Pytorch TorchAIMmaitre314 PicklescanAI | 23/6/2026 | 30/9/2026 | picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded in pickle files. Attackers can craft malicious pickle files that bypass picklescan detection and execute arbitrary code when loaded via pickle.load(). | |
| Aplazada | Alta (7.1) | 0.69% | — | PytorchAIMmaitre314 PicklescanAI | 17/6/2026 | 17/6/2026 | picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed malicious magic numbers via dynamic eval using the __reduce__ trick. Attackers can craft malicious PyTorch payloads that evade picklescan detection while remaining executable, enabling arbitrary… |