Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 0.62% | — | Xbifrost BifrostAI | 14/9/2026 | 18/9/2026 | Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Bifrost Vtoken-mintingAIBifrost SlpxAI | 8/9/2026 | 10/9/2026 | The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an… | |
| Pendiente de análisis | Alta (7.7) | 0.13% | — | ARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAIARM 5TH GEN GPU Architecture Kernel DriverAI | 8/9/2026 | 10/9/2026 | A race condition vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to cause a denial of service or disclose sensitive information. This… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | ARM Bifrost GPU Userspace DriverAIARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel… | |
| Pendiente de análisis | Media (5.1) | 0.11% | — | ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel… | |
| Pendiente de análisis | Media (4) | 0.11% | — | ARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAIARM 5TH GEN GPU Architecture Kernel DriverAI | 8/9/2026 | 10/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel… | |
| Pendiente de análisis | Media (4.4) | 0.17% | — | ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI | 8/9/2026 | 8/9/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel… | |
| Pendiente de análisis | Alta (8.1) | 3.6% | — | Xbifrost BifrostAI | 6/9/2026 | 9/9/2026 | Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefixed path as a download URL, writes the… | |
| Aplazada | Alta (8.7) | 0.61% | — | Xbifrost BifrostAI | 28/8/2026 | 9/9/2026 | Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, classifies Carrier-Grade NAT 100.64.0.0/10, IPv6 6to4 2002::/16, NAT64 64:ff9b::/96… | |
| Aplazada | Alta (7.2) | 0.59% | — | Frostming UnearthAI | 10/8/2026 | 24/9/2026 | unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal… | |
| Aplazada | Alta (8.4) | 0.19% | — | Frostming PDMAI | 4/8/2026 | 8/9/2026 | PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute arbitrary Python code before any command is… | |
| Aplazada | Alta (8.4) | 0.20% | — | Frostming PDMAI | 4/8/2026 | 8/9/2026 | pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add symlink/hardlink support but replaces the safe… | |
| Aplazada | Media (6.8) | 0.20% | — | Frostming PDMAI | 4/8/2026 | 8/9/2026 | pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository places those files as symlinks, local PDM operations can overwrite the symlink targets.… | |
| Aplazada | Baja (2.1) | 0.32% | — | Autohomecorp FrostmourneAI | 5/4/2026 | 24/7/2026 | A security flaw has been discovered in AutohomeCorp frostmourne up to 1.0. Affected is the function httpTest of the file /api/monitor-api/alarm/previewData of the component Alarm Preview. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may… | |
| Aplazada | Baja (2.1) | 0.35% | — | Autohomecorp FrostmourneAI | 1/4/2026 | 17/6/2026 | A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src/main/java/com/autohome/frostmourne/monitor/controller/AlarmController.java of the component Alarm Preview. Executing a manipulation can lead to server-side request… | |
| Aplazada | Baja (2.1) | 0.39% | — | Autohomecorp FrostmourneAIOracle Nashorn Javascript EngineAI | 12/3/2026 | 17/6/2026 | A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of the component Oracle Nashorn JavaScript Engine. Such manipulation of the argument EXPRESSION leads to code injection. The attack can be executed remotely. The exploit has… | |
| Aplazada | Alta (8.8) | 0.36% | — | WpbifrostAI | 15/10/2025 | 17/6/2026 | The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ctl_create_link AJAX action in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (5.1) | 0.14% | — | FrostwireAI | 2/10/2025 | 17/6/2026 | FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBRARIES environment variable. This allows escalated privileges to arbitrary… | |
| Analizada | Media (5.3) | 0.33% | — | ARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Valhall GPU Kernel Driver | 8/9/2025 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU… | |
| Aplazada | Media (6) | 0.29% | — | ZF FrostAI | 5/9/2025 | 17/6/2026 | ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 through 2.1.0, refresh shares with smaller min_signers will reduce security of group. The inability to change min_signers (i.e. the threshold) with the refresh share functionality… | |
| Analizada | Media (4.3) | 0.26% | — | ARM 5TH GEN GPU Architecture Userspace DriverARM Bifrost GPU Userspace DriverARM Valhall GPU Userspace Driver | 4/8/2025 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to gain access to already freed memory.This… | |
| Analizada | Alta (7.8) | 0.16% | — | ARM 5TH GEN GPU Architecture Userspace DriverARM Bifrost GPU Userspace DriverARM Valhall GPU Userspace Driver | 2/6/2025 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL… | |
| Analizada | Alta (7.8) | 0.16% | — | ARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Valhall GPU Kernel Driver | 2/6/2025 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU… |