Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.35%—Clink Bitcoin Lightning Payment GatewayAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
AnalizadaAlta (8.4)0.63%—Lightningai Pytorch Lightning15/7/20266/8/2026
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True…
ModificadaCrítica (9.3)0.67%—Lightningai Pytorch Lightning14/5/202615/7/2026
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
ModificadaAlta (7.8)0.55%—Lightningai Pytorch Lightning12/5/202617/6/2026
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive…
AplazadaAlta (8.4)0.19%—Lightning Flow ScannerAI12/12/202517/6/2026
Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows. Versions 6.10.5 and below allow a maliciously crafted flow metadata file to cause arbitrary JavaScript execution during scanning. The APIVersion rule uses new Function() to evaluate…
ModificadaAlta (7.5)0.63%—Lightningai Pytorch Lightning20/3/202517/6/2026
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down.
AnalizadaCrítica (9.1)1.1%—Lightningai Pytorch Lightning20/3/202517/6/2026
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote…
AplazadaBaja (1.3)0.43%—Maxd Lightning ModuleAIOpencartAI3/2/202517/6/2026
A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can lead to deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed…
AplazadaMedia (6.1)0.36%—Bitcoin Lightning PublisherAI24/12/202417/6/2026
The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
ModificadaCrítica (9.8)1.3%—Lightningai Pytorch Lightning27/6/202417/6/2026
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal…
AplazadaMedia (6.5)0.57%—Lightning Network Daemon LNDAI20/6/202417/6/2026
The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The issue was patched in lnd v0.17.0. Users should update to a version > v0.17.0 to be protected. Users…
ModificadaCrítica (9.8)27%—Lightningai Pytorch Lightning6/6/202417/6/2026
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. The library uses `deepdiff.Delta` objects to modify application state based on frontend…
AplazadaMedia (4.3)0.37%—Hidekazu Ishikawa X-t9AIThemeinwp Default MAGAIOUT THE BOX NamahaAIOUT THE BOX CitylogicAI+1110/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes…
ModificadaMedia (6.5)1.1%—Btcd Project BtcdLightning Network Daemon Project Lightning Network Daemon17/11/202217/6/2026
Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can continue to make payments and forward HTLCs,…
ModificadaCrítica (9.8)1.00%—Lightningai Pytorch Lightning5/3/202217/6/2026
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
ModificadaAlta (7.8)0.98%—Lightningai Pytorch Lightning23/12/202117/6/2026
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
ModificadaAlta (8.6)1.9%—Lightning Network Daemon Project Lightning Network Daemon4/10/202117/6/2026
Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure.
ModificadaCrítica (9.4)1.5%—Elementsproject C-lightning4/10/202117/6/2026
Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.
ModificadaAlta (8.2)0.74%—Lightning Network Daemon Project Lightning Network Daemon21/10/202017/6/2026
Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before releasing the preimage. In the case of a hash-and-amount collision with an…
ModificadaMedia (5.3)0.71%—Lightning Network Daemon Project Lightning Network Daemon21/10/202017/6/2026
Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver, or…
ModificadaMedia (6.3)0.86%—Lightning-viz Lightning20/10/202017/6/2026
This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller.
ModificadaAlta (7.5)2.2%—Lightning Network Daemon31/1/202017/6/2026
Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control.
ModificadaAlta (7.5)1.8%—Elementsproject C-lightning31/1/202017/6/2026
c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "It can be used for testing, but it should not be used for real funds."