Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.48% | — | Refinedev InferencerAI | 16/9/2026 | 24/9/2026 | @refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders. | |
| Pendiente de análisis | Alta (7.5) | 0.56% | — | Nvidia Triton Inference ServerAI | 8/9/2026 | 8/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. | |
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Nvidia Triton Inference ServerAI | 8/9/2026 | 8/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (8.7) | 0.61% | — | XinferenceAI | 4/9/2026 | 24/9/2026 | Xinference (affected commit 4a94832, v3.x) contains an unauthenticated arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-register endpoint, which accepts a caller-supplied model_path parameter without authentication or path confinement. The endpoint reads and parses config.json,… | |
| Aplazada | Alta (8.7) | 1.0% | — | XinferenceAI | 24/8/2026 | 1/10/2026 | Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional default: RerankModel._get_tokenizer in xinference/model/rerank/core.py,… | |
| Aplazada | Crítica (10) | 1.2% | — | XinferenceAI | 21/8/2026 | 30/9/2026 | Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py. Requests to /v1/chat/completions with a… | |
| Analizada | Media (5.5) | 0.18% | — | Nvidia Triton Inference Server | 18/8/2026 | 1/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution. | |
| Analizada | Alta (7.5) | 0.67% | — | Nvidia Triton Inference Server | 18/8/2026 | 1/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service. | |
| Analizada | Alta (7.5) | 0.67% | — | Nvidia Triton Inference Server | 18/8/2026 | 1/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service. | |
| Analizada | Crítica (9.8) | 0.73% | — | Nvidia Triton Inference Server | 18/8/2026 | 2/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service. | |
| Analizada | Crítica (9.1) | 0.74% | — | Nvidia Triton Inference Server | 18/8/2026 | 2/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure. | |
| Analizada | Media (5.4) | 0.16% | — | Intel Approximate Bayesian Inference Framework | 11/8/2026 | 2/10/2026 | Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit #484c949 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This… | |
| Analizada | Alta (7.1) | 0.23% | — | Nvidia Triton Inference Server | 4/8/2026 | 17/8/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information… | |
| Aplazada | Media (6.9) | 0.43% | — | Huggingface Text-generation-inferenceAI | 16/7/2026 | 16/7/2026 | text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the server into issuing arbitrary HTTP GET requests by supplying a crafted image_url value in chat… | |
| Aplazada | Alta (7.5) | 0.49% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Media (6.5) | 0.44% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Alta (7.5) | 0.49% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.5) | 0.49% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.5) | 0.53% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.5) | 0.53% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Alta (7.5) | 0.54% | — | Nvidia Triton Inference Server | 14/7/2026 | 4/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Alta (7.5) | 0.67% | — | Nvidia Triton Inference Server | 1/7/2026 | 6/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Alta (7.5) | 0.72% | — | Nvidia Triton Inference Server | 1/7/2026 | 6/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Media (6.5) | 7.1% | ⚠ Explotación activa | Encode StarletteRedhat AI Inference ServerRedhat Ansible Automation PlatformRedhat Migration Toolkit FOR Applications+4 | 26/5/2026 | 1/10/2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make… | |
| Analizada | Alta (7.5) | 0.41% | — | Nvidia Triton Inference Server | 20/5/2026 | 24/7/2026 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. |