scikit-learn records
3 published records for vendor scikit-learn.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-502 Deserialization of Untrusted Data1
- CWE-921 Storage of Sensitive Data in a Mechanism without Access Control1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-13092No exploit | scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() fuscikit-learn · scikit-learn · CWE-502 | Critical9.8 | — | 3.4% | May 15, 2020 |
31Monitor | CVE-2020-28975No exploit | svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of serviscikit-learn · scikit-learn | High7.5 | — | 3.5% | Nov 21, 2020 |
18Monitor | CVE-2024-5206No exploit | Sensitive Data Leakage in sklearn.feature_extraction.text.TfidfVectorizer in scikit-learn/scikit-learnscikit-learn · scikit-learn · CWE-921 | Medium4.7 | — | 0.2% | Jun 6, 2024 |
- CVE-2020-1309240Plan
scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() fu
CriticalCVSS 9.8No exploitEPSS 3%scikit-learn · scikit-learnMay 15, 2020
- CVE-2020-2897531Monitor
svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of servi
HighCVSS 7.5No exploitEPSS 4%scikit-learn · scikit-learnNov 21, 2020
- CVE-2024-520618Monitor
Sensitive Data Leakage in sklearn.feature_extraction.text.TfidfVectorizer in scikit-learn/scikit-learn
MediumCVSS 4.7No exploitEPSS 0%scikit-learn · scikit-learnJun 6, 2024