Stanford
Products
5- 5 CVEs
- Dspy2 CVEspypi
- 2 CVEs
- 1 CVE
- 1 CVE
Recent CVEs
11| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39020 | Cri | 0.57 | 9.8 | 0.01 | Jul 28, 2023 | stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument. | ||
| CVE-2021-44550 | Cri | 0.57 | 9.8 | 0.01 | Feb 24, 2022 | An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159). | ||
| CVE-2022-0239 | Cri | 0.57 | 9.8 | 0.01 | Jan 17, 2022 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference | ||
| CVE-2021-3878 | Cri | 0.57 | 9.8 | 0.02 | Oct 15, 2021 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference | ||
| CVE-2026-72742 | Hig | 0.49 | 8.6 | 0.00 | Aug 11, 2026 | DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url field of a parsed Image or Audio typed… | ||
| CVE-2013-2106 | Hig | 0.49 | 7.5 | 0.02 | Dec 3, 2019 | webauth before 4.6.1 has authentication credential disclosure | ||
| CVE-2026-54499 | Hig | 0.42 | 7.5 | 0.00 | Jul 8, 2026 | Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(..., weights_only=True) but fall back to… | ||
| CVE-2021-3869 | Hig | 0.42 | 7.5 | 0.01 | Oct 19, 2021 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference | ||
| CVE-2022-0198 | Hig | 0.39 | 7.1 | 0.01 | Jan 13, 2022 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference | ||
| CVE-2025-12695 | Med | 0.38 | 5.9 | 0.00 | Nov 4, 2025 | The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. | ||
| CVE-2009-2945 | 0.00 | — | 0.01 | Sep 15, 2009 | weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by… |
- risk 0.57cvss 9.8epss 0.01
stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.
- risk 0.57cvss 9.8epss 0.01
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
- risk 0.57cvss 9.8epss 0.01
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
- risk 0.57cvss 9.8epss 0.02
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
- risk 0.49cvss 8.6epss 0.00
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url field of a parsed Image or Audio typed…
- risk 0.49cvss 7.5epss 0.02
webauth before 4.6.1 has authentication credential disclosure
- risk 0.42cvss 7.5epss 0.00
Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(..., weights_only=True) but fall back to…
- risk 0.42cvss 7.5epss 0.01
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
- risk 0.39cvss 7.1epss 0.01
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
- risk 0.38cvss 5.9epss 0.00
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.
- CVE-2009-2945Sep 15, 2009risk 0.00cvss —epss 0.01
weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by…