Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

74 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.20%—Linuxfoundation Pytorch31/3/202517/6/2026
A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (4.8)0.20%—Linuxfoundation Pytorch31/3/202517/6/2026
A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (4.8)0.20%—Linuxfoundation Pytorch31/3/202517/6/2026
A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (4.8)0.20%—Linuxfoundation Pytorch31/3/202517/6/2026
A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be…
ModificadaMedia (4.8)0.26%—Linuxfoundation Pytorch30/3/202517/6/2026
A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real…
ModificadaAlta (7.5)0.63%—Lightningai Pytorch Lightning20/3/202517/6/2026
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down.
AnalizadaCrítica (9.1)1.1%—Lightningai Pytorch Lightning20/3/202517/6/2026
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote…
AplazadaMedia (6.3)0.39%—Pytorch ServeAI20/3/202517/6/2026
In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This could lead to potential security vulnerabilities or unauthorized access to the bucket if it is not properly secured or…
AplazadaCrítica (9.8)6.0%💥 ExploitInvoke-ai InvokeaiAIPytorch TorchAI20/3/202517/6/2026
A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files,…
AnalizadaBaja (2)0.26%—Linuxfoundation Pytorch10/3/202517/6/2026
A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity…
AnalizadaBaja (2.3)0.44%—Linuxfoundation Pytorch10/3/202517/6/2026
A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The…
AnalizadaCrítica (9.8)1.6%—Linuxfoundation Pytorch29/10/202417/6/2026
In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
AnalizadaAlta (8.2)0.64%—Pytorch Torchserve19/7/202417/6/2026
TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions the two gRPC ports 7070 and 7071, are not bound to [localhost](http://localhost/) by default, so when TorchServe is launched, these two interfaces are bound to all interfaces. Customers using…
AnalizadaCrítica (9.8)0.80%—Pytorch Torchserve19/7/202417/6/2026
TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check on allowed_urls configuration can be by-passed if the URL contains characters such as ".." but it does not prevent the model from being downloaded into the model store. Once a file is downloaded, it…
ModificadaCrítica (9.8)1.3%—Lightningai Pytorch Lightning27/6/202417/6/2026
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal…
ModificadaCrítica (9.8)27%💥 PoCLightningai Pytorch Lightning6/6/202417/6/2026
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. The library uses `deepdiff.Delta` objects to modify application state based on frontend…
AnalizadaMedia (5.5)0.38%—Linuxfoundation Pytorch19/4/202417/6/2026
Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.
AnalizadaAlta (7.8)0.27%—Linuxfoundation Pytorch17/4/202417/6/2026
Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.
AnalizadaMedia (4)0.22%—Linuxfoundation Pytorch17/4/202417/6/2026
PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaMedia (5.3)0.68%—Pytorch Torchserve21/11/202317/6/2026
TorchServe is a tool for serving and scaling PyTorch models in production. Starting in version 0.1.0 and prior to version 0.9.0, using the model/workflow management API, there is a chance of uploading potentially harmful archives that contain files that are extracted to any location on the filesystem that is within…
ModificadaCrítica (9.8)44%💥 ExploitPytorch Torchserve28/9/202317/6/2026
TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote HTTP download requests and write files to the disk. This issue could be taken advantage of to compromise the integrity of the system and…
ModificadaCrítica (9.8)1.3%—Linuxfoundation Pytorch26/11/202217/6/2026
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
ModificadaCrítica (9.8)1.00%—Lightningai Pytorch Lightning5/3/202217/6/2026
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
ModificadaAlta (7.8)0.98%—Lightningai Pytorch Lightning23/12/202117/6/2026
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
Orbitaley — Vulnerabilidades