Vulnerabilities
33 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-1603 | paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file. paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2024-0917 | remote code execution in paddlepaddle/paddle 2.6.0 remote code execution in paddlepaddle/paddle 2.6.0 NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2024-0521 | Code Injection in paddlepaddle/paddle Code Injection in paddlepaddle/paddle NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2023-52314 | PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2023-38673 | PaddlePaddle before 2.5.0 has a command injection in fs.py. PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2022-46742 +1 in the same advisory: …46741 | Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution. Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2022-45908 | In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2022-31523 | The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. NVD description · AI analysis pending | 9.3 | 1% | PoC |
| — |