Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.57% | — | Lightning Network Daemon LNDAI | 20/6/2024 | 17/6/2026 | The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The issue was patched in lnd v0.17.0. Users should update to a version > v0.17.0 to be protected. Users… | |
| Modificada | Media (6.5) | 1.1% | — | Btcd Project BtcdLightning Network Daemon Project Lightning Network Daemon | 17/11/2022 | 17/6/2026 | Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can continue to make payments and forward HTLCs,… | |
| Modificada | Alta (8.6) | 1.9% | — | Lightning Network Daemon Project Lightning Network Daemon | 4/10/2021 | 17/6/2026 | Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure. | |
| Modificada | Alta (8.2) | 0.74% | — | Lightning Network Daemon Project Lightning Network Daemon | 21/10/2020 | 17/6/2026 | Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before releasing the preimage. In the case of a hash-and-amount collision with an… | |
| Modificada | Media (5.3) | 0.71% | — | Lightning Network Daemon Project Lightning Network Daemon | 21/10/2020 | 17/6/2026 | Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver, or… | |
| Modificada | Alta (7.5) | 2.2% | — | Lightning Network Daemon | 31/1/2020 | 17/6/2026 | Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control. |