Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.35% | — | Clink Bitcoin Lightning Payment GatewayAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | |
| Analizada | Alta (8.4) | 0.63% | — | Lightningai Pytorch Lightning | 15/7/2026 | 6/8/2026 | PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True… | |
| Modificada | Crítica (9.3) | 0.67% | — | Lightningai Pytorch Lightning | 14/5/2026 | 15/7/2026 | PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism. | |
| Modificada | Alta (7.8) | 0.55% | — | Lightningai Pytorch Lightning | 12/5/2026 | 17/6/2026 | PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive… | |
| Aplazada | Alta (8.4) | 0.19% | — | Lightning Flow ScannerAI | 12/12/2025 | 17/6/2026 | Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows. Versions 6.10.5 and below allow a maliciously crafted flow metadata file to cause arbitrary JavaScript execution during scanning. The APIVersion rule uses new Function() to evaluate… | |
| Modificada | Alta (7.5) | 0.63% | — | Lightningai Pytorch Lightning | 20/3/2025 | 17/6/2026 | A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down. | |
| Analizada | Crítica (9.1) | 1.1% | — | Lightningai Pytorch Lightning | 20/3/2025 | 17/6/2026 | In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote… | |
| Aplazada | Baja (1.3) | 0.43% | — | Maxd Lightning ModuleAIOpencartAI | 3/2/2025 | 17/6/2026 | A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can lead to deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed… | |
| Aplazada | Media (6.1) | 0.36% | — | Bitcoin Lightning PublisherAI | 24/12/2024 | 17/6/2026 | The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Crítica (9.8) | 1.3% | — | Lightningai Pytorch Lightning | 27/6/2024 | 17/6/2026 | A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal… | |
| Aplazada | Media (6.5) | 0.57% | — | Lightning Network Daemon LNDAI | 20/6/2024 | 17/6/2026 | The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The issue was patched in lnd v0.17.0. Users should update to a version > v0.17.0 to be protected. Users… | |
| Modificada | Crítica (9.8) | 27% | — | Lightningai Pytorch Lightning | 6/6/2024 | 17/6/2026 | A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. The library uses `deepdiff.Delta` objects to modify application state based on frontend… | |
| Aplazada | Media (4.3) | 0.37% | — | Hidekazu Ishikawa X-t9AIThemeinwp Default MAGAIOUT THE BOX NamahaAIOUT THE BOX CitylogicAI+11 | 10/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes… | |
| Modificada | Media (6.5) | 1.1% | — | Btcd Project BtcdLightning Network Daemon Project Lightning Network Daemon | 17/11/2022 | 17/6/2026 | Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can continue to make payments and forward HTLCs,… | |
| Modificada | Crítica (9.8) | 1.00% | — | Lightningai Pytorch Lightning | 5/3/2022 | 17/6/2026 | Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0. | |
| Modificada | Alta (7.8) | 0.98% | — | Lightningai Pytorch Lightning | 23/12/2021 | 17/6/2026 | pytorch-lightning is vulnerable to Deserialization of Untrusted Data | |
| Modificada | Alta (8.6) | 1.9% | — | Lightning Network Daemon Project Lightning Network Daemon | 4/10/2021 | 17/6/2026 | Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure. | |
| Modificada | Crítica (9.4) | 1.5% | — | Elementsproject C-lightning | 4/10/2021 | 17/6/2026 | Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure. | |
| Modificada | Alta (8.2) | 0.74% | — | Lightning Network Daemon Project Lightning Network Daemon | 21/10/2020 | 17/6/2026 | Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before releasing the preimage. In the case of a hash-and-amount collision with an… | |
| Modificada | Media (5.3) | 0.71% | — | Lightning Network Daemon Project Lightning Network Daemon | 21/10/2020 | 17/6/2026 | Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver, or… | |
| Modificada | Media (6.3) | 0.86% | — | Lightning-viz Lightning | 20/10/2020 | 17/6/2026 | This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller. | |
| Modificada | Alta (7.5) | 2.2% | — | Lightning Network Daemon | 31/1/2020 | 17/6/2026 | Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control. | |
| Modificada | Alta (7.5) | 1.8% | — | Elementsproject C-lightning | 31/1/2020 | 17/6/2026 | c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "It can be used for testing, but it should not be used for real funds." |