Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
114 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.20% | — | Linuxfoundation Pytorch | 31/3/2025 | 17/6/2026 | A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (4.8) | 0.20% | — | Linuxfoundation Pytorch | 31/3/2025 | 17/6/2026 | A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (4.8) | 0.26% | — | Linuxfoundation Pytorch | 30/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real… | |
| Modificada | Alta (7.5) | 0.63% | — | Lightningai Pytorch Lightning | 20/3/2025 | 17/6/2026 | A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down. | |
| Analizada | Crítica (9.1) | 1.1% | — | Lightningai Pytorch Lightning | 20/3/2025 | 17/6/2026 | In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote… | |
| Aplazada | Media (6.3) | 0.39% | — | Pytorch ServeAI | 20/3/2025 | 17/6/2026 | In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This could lead to potential security vulnerabilities or unauthorized access to the bucket if it is not properly secured or… | |
| Aplazada | Crítica (9.8) | 6.0% | 💥 Exploit | Invoke-ai InvokeaiAIPytorch TorchAI | 20/3/2025 | 17/6/2026 | A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability arises from unsafe deserialization of model files using torch.load without proper validation. Attackers can exploit this by embedding malicious code in model files,… | |
| Analizada | Baja (2) | 0.26% | — | Linuxfoundation Pytorch | 10/3/2025 | 17/6/2026 | A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity… | |
| Analizada | Baja (2.3) | 0.44% | — | Linuxfoundation Pytorch | 10/3/2025 | 17/6/2026 | A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The… | |
| Analizada | Alta (8.1) | 1.2% | — | Microsoft Torchgeo | 12/11/2024 | 17/6/2026 | TorchGeo Remote Code Execution Vulnerability | |
| Analizada | Crítica (9.8) | 1.6% | — | Linuxfoundation Pytorch | 29/10/2024 | 17/6/2026 | In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing. | |
| Analizada | Alta (8.2) | 0.64% | — | Pytorch Torchserve | 19/7/2024 | 17/6/2026 | TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions the two gRPC ports 7070 and 7071, are not bound to [localhost](http://localhost/) by default, so when TorchServe is launched, these two interfaces are bound to all interfaces. Customers using… | |
| Analizada | Crítica (9.8) | 0.80% | — | Pytorch Torchserve | 19/7/2024 | 17/6/2026 | TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check on allowed_urls configuration can be by-passed if the URL contains characters such as ".." but it does not prevent the model from being downloaded into the model store. Once a file is downloaded, it… | |
| Analizada | Media (4.9) | 0.61% | — | Torchbox Wagtail | 11/7/2024 | 17/6/2026 | Wagtail is an open source content management system built on Django. A bug in Wagtail's `parse_query_string` would result in it taking a long time to process suitably crafted inputs. When used to parse sufficiently long strings of characters without a space, `parse_query_string` would take an unexpectedly large amount… | |
| Modificada | Crítica (9.8) | 1.3% | — | Lightningai Pytorch Lightning | 27/6/2024 | 17/6/2026 | A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal… | |
| Modificada | Crítica (9.8) | 27% | 💥 PoC | Lightningai Pytorch Lightning | 6/6/2024 | 17/6/2026 | A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. The library uses `deepdiff.Delta` objects to modify application state based on frontend… | |
| Aplazada | Media (5.5) | 0.33% | — | DjangoAITorchbox WagtailAI | 30/5/2024 | 17/6/2026 | Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with access to the Wagtail admin and knowledge of the URL of the edit view for a settings model can access and update that setting, even when they have not… | |
| Aplazada | Baja (2.7) | 0.48% | — | DjangoAITorchbox WagtailAI | 2/5/2024 | 17/6/2026 | Wagtail is an open source content management system built on Django. In affected versions if a model has been made available for editing through the `wagtail.contrib.settings` module or `ModelViewSet`, and the `permission` argument on `FieldPanel` has been used to further restrict access to one or more fields of the… | |
| Analizada | Media (5.5) | 0.38% | — | Linuxfoundation Pytorch | 19/4/2024 | 17/6/2026 | Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp. | |
| Analizada | Alta (7.8) | 0.27% | — | Linuxfoundation Pytorch | 17/4/2024 | 17/6/2026 | Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp. | |
| Analizada | Media (4) | 0.22% | — | Linuxfoundation Pytorch | 17/4/2024 | 17/6/2026 | PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Modificada | Media (5.3) | 0.68% | — | Pytorch Torchserve | 21/11/2023 | 17/6/2026 | TorchServe is a tool for serving and scaling PyTorch models in production. Starting in version 0.1.0 and prior to version 0.9.0, using the model/workflow management API, there is a chance of uploading potentially harmful archives that contain files that are extracted to any location on the filesystem that is within… | |
| Modificada | Baja (2.7) | 0.45% | — | Torchbox Wagtail | 19/10/2023 | 17/6/2026 | Wagtail is an open source content management system built on Django. A user with a limited-permission editor account for the Wagtail admin can make a direct URL request to the admin view that handles bulk actions on user accounts. While authentication rules prevent the user from making any changes, the error message… | |
| Modificada | Crítica (9.8) | 42% | 💥 Exploit | Pytorch Torchserve | 28/9/2023 | 17/6/2026 | TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote HTTP download requests and write files to the disk. This issue could be taken advantage of to compromise the integrity of the system and… | |
| Modificada | Media (4.9) | 1.1% | — | Torchbox Wagtail | 3/4/2023 | 17/6/2026 | Wagtail is an open source content management system built on Django. Prior to versions 4.1.4 and 4.2.2, a memory exhaustion bug exists in Wagtail's handling of uploaded images and documents. For both images and documents, files are loaded into memory during upload for additional processing. A user with access to… |