Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

63 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.8)0.62%—Xbifrost BifrostAI14/9/202618/9/2026
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One…
AplazadaCrítica (9.1)0.42%—Bifrost Vtoken-mintingAIBifrost SlpxAI8/9/202610/9/2026
The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an…
Pendiente de análisisAlta (7.7)0.13%—ARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAIARM 5TH GEN GPU Architecture Kernel DriverAI8/9/202610/9/2026
A race condition vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to cause a denial of service or disclose sensitive information. This…
Pendiente de análisisAlta (7.8)0.16%—ARM Bifrost GPU Userspace DriverAIARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue…
Pendiente de análisisAlta (7.8)0.16%—ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel…
Pendiente de análisisAlta (7.8)0.16%—ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel…
Pendiente de análisisMedia (5.1)0.11%—ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel…
Pendiente de análisisMedia (4)0.11%—ARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAIARM 5TH GEN GPU Architecture Kernel DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel…
Pendiente de análisisMedia (4.4)0.17%—ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI8/9/20268/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel…
Pendiente de análisisAlta (8.1)3.6%—Xbifrost BifrostAI6/9/20269/9/2026
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefixed path as a download URL, writes the…
AplazadaAlta (8.7)0.61%—Xbifrost BifrostAI28/8/20269/9/2026
Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, classifies Carrier-Grade NAT 100.64.0.0/10, IPv6 6to4 2002::/16, NAT64 64:ff9b::/96…
AplazadaAlta (7.2)0.59%—Frostming UnearthAI10/8/202624/9/2026
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal…
AplazadaAlta (8.4)0.19%—Frostming PDMAI4/8/20268/9/2026
PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute arbitrary Python code before any command is…
AplazadaAlta (8.4)0.20%—Frostming PDMAI4/8/20268/9/2026
pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add symlink/hardlink support but replaces the safe…
AplazadaMedia (6.8)0.20%—Frostming PDMAI4/8/20268/9/2026
pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository places those files as symlinks, local PDM operations can overwrite the symlink targets.…
AplazadaBaja (2.1)0.32%—Autohomecorp FrostmourneAI5/4/202624/7/2026
A security flaw has been discovered in AutohomeCorp frostmourne up to 1.0. Affected is the function httpTest of the file /api/monitor-api/alarm/previewData of the component Alarm Preview. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may…
AplazadaBaja (2.1)0.35%—Autohomecorp FrostmourneAI1/4/202617/6/2026
A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src/main/java/com/autohome/frostmourne/monitor/controller/AlarmController.java of the component Alarm Preview. Executing a manipulation can lead to server-side request…
AplazadaBaja (2.1)0.39%—Autohomecorp FrostmourneAIOracle Nashorn Javascript EngineAI12/3/202617/6/2026
A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of the component Oracle Nashorn JavaScript Engine. Such manipulation of the argument EXPRESSION leads to code injection. The attack can be executed remotely. The exploit has…
AplazadaAlta (8.8)0.36%—WpbifrostAI15/10/202517/6/2026
The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ctl_create_link AJAX action in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaMedia (5.1)0.14%—FrostwireAI2/10/202517/6/2026
FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBRARIES environment variable. This allows escalated privileges to arbitrary…
AnalizadaMedia (5.3)0.33%—ARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Valhall GPU Kernel Driver8/9/202517/6/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU…
AplazadaMedia (6)0.29%—ZF FrostAI5/9/202517/6/2026
ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 through 2.1.0, refresh shares with smaller min_signers will reduce security of group. The inability to change min_signers (i.e. the threshold) with the refresh share functionality…
AnalizadaMedia (4.3)0.26%—ARM 5TH GEN GPU Architecture Userspace DriverARM Bifrost GPU Userspace DriverARM Valhall GPU Userspace Driver4/8/202517/6/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to gain access to already freed memory.This…
AnalizadaAlta (7.8)0.16%—ARM 5TH GEN GPU Architecture Userspace DriverARM Bifrost GPU Userspace DriverARM Valhall GPU Userspace Driver2/6/202517/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL…
AnalizadaAlta (7.8)0.16%—ARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Valhall GPU Kernel Driver2/6/202517/6/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU…