paddlepaddle CVE Vulnerabilities & Metrics

Focus on paddlepaddle vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About paddlepaddle Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with paddlepaddle. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total paddlepaddle CVEs: 33
Earliest CVE date: 11 Jul 2022, 01:15 UTC
Latest CVE date: 23 Mar 2024, 19:15 UTC

Latest CVE reference: CVE-2024-1603

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -96.43%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -96.43%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical paddlepaddle CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.19

Max CVSS: 6.4

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 32
4.0-6.9 1
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS paddlepaddle CVEs

These are the five CVEs with the highest CVSS scores for paddlepaddle, sorted by severity first and recency.

All CVEs for paddlepaddle

CVE-2024-1603 paddlepaddle vulnerability CVSS: 0 23 Mar 2024, 19:15 UTC

paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.

CVE-2024-0818 paddlepaddle vulnerability CVSS: 0 07 Mar 2024, 13:15 UTC

Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6

CVE-2024-0917 paddlepaddle vulnerability CVSS: 0 07 Mar 2024, 09:15 UTC

remote code execution in paddlepaddle/paddle 2.6.0

CVE-2024-0815 paddlepaddle vulnerability CVSS: 0 07 Mar 2024, 04:15 UTC

Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

CVE-2024-0817 paddlepaddle vulnerability CVSS: 0 07 Mar 2024, 02:15 UTC

Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

CVE-2024-0521 paddlepaddle vulnerability CVSS: 0 20 Jan 2024, 21:15 UTC

Code Injection in paddlepaddle/paddle

CVE-2023-52314 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system.

CVE-2023-52313 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-52312 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

Nullptr dereference in paddle.crop in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-52311 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system.

CVE-2023-52310 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.

CVE-2023-52309 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.

CVE-2023-52308 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-52307 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

CVE-2023-52306 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-52305 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-52304 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

CVE-2023-52303 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

Nullptr in paddle.put_along_axis in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-52302 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

Nullptr in paddle.nextafter in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-38678 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

OOB access in paddle.mode in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-38677 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

FPE in paddle.linalg.eig in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-38676 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

Nullptr in paddle.dot in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-38675 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

FPE in paddle.linalg.matrix_rank in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-38674 paddlepaddle vulnerability CVSS: 0 03 Jan 2024, 09:15 UTC

FPE in paddle.nanmedian in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-38673 paddlepaddle vulnerability CVSS: 0 26 Jul 2023, 12:15 UTC

PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.

CVE-2023-38672 paddlepaddle vulnerability CVSS: 0 26 Jul 2023, 12:15 UTC

FPE in paddle.trace in PaddlePaddle before 2.5.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-38671 paddlepaddle vulnerability CVSS: 0 26 Jul 2023, 11:15 UTC

Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.

CVE-2023-38670 paddlepaddle vulnerability CVSS: 0 26 Jul 2023, 11:15 UTC

Null pointer dereference in paddle.flip in PaddlePaddle before 2.5.0. This resulted in a runtime crash and denial of service.

CVE-2023-38669 paddlepaddle vulnerability CVSS: 0 26 Jul 2023, 10:15 UTC

Use after free in paddle.diagonal in PaddlePaddle before 2.5.0. This resulted in a potentially exploitable condition.

CVE-2022-46742 paddlepaddle vulnerability CVSS: 0 07 Dec 2022, 09:15 UTC

Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.

CVE-2022-46741 paddlepaddle vulnerability CVSS: 0 07 Dec 2022, 08:15 UTC

Out-of-bounds read in gather_tree in PaddlePaddle before 2.4. 

CVE-2022-45908 paddlepaddle vulnerability CVSS: 0 26 Nov 2022, 02:15 UTC

In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.

CVE-2022-31523 paddlepaddle vulnerability CVSS: 6.4 11 Jul 2022, 01:15 UTC

The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.