ZeroHour

Vulnerabilities

33 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1603
paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.

paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.

NVD description · AI analysis pending
7.5<1% PoC
  • paddlepaddle paddlepaddle
CVE-2024-0917
+3 in the same advisory: …0818 …0815 …0817
remote code execution in paddlepaddle/paddle 2.6.0

remote code execution in paddlepaddle/paddle 2.6.0

NVD description · AI analysis pending
9.8
group max
2% PoC
  • paddlepaddle paddlepaddle
CVE-2024-0521
Code Injection in paddlepaddle/paddle

Code Injection in paddlepaddle/paddle

NVD description · AI analysis pending
7.8<1% PoC
  • paddlepaddle paddle
CVE-2023-52314
PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare.

PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system.

NVD description · AI analysis pending
9.8
group max
1%
  • paddlepaddle paddlepaddle
CVE-2023-38673
+4 in the same advisory: …38669 …38671 …38672 …38670
PaddlePaddle before 2.5.0 has a command injection in fs.py.

PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • paddlepaddle paddlepaddle
CVE-2022-46742
+1 in the same advisory: …46741
Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.

Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • paddlepaddle paddlepaddle
CVE-2022-45908
In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr.

In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.

NVD description · AI analysis pending
9.81% PoC
  • paddlepaddle paddlepaddle
CVE-2022-31523
The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

NVD description · AI analysis pending
9.31% PoC
  • paddlepaddle anakin