Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

78 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.7)0.48%—Refinedev InferencerAI16/9/202624/9/2026
@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.
Pendiente de análisisAlta (7.5)0.56%—Nvidia Triton Inference ServerAI8/9/20268/9/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
Pendiente de análisisAlta (7.5)0.47%—Nvidia Triton Inference ServerAI8/9/20268/9/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (8.7)0.61%—XinferenceAI4/9/202624/9/2026
Xinference (affected commit 4a94832, v3.x) contains an unauthenticated arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-register endpoint, which accepts a caller-supplied model_path parameter without authentication or path confinement. The endpoint reads and parses config.json,…
AplazadaAlta (8.7)1.0%—XinferenceAI24/8/20261/10/2026
Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional default: RerankModel._get_tokenizer in xinference/model/rerank/core.py,…
AplazadaCrítica (10)1.2%—XinferenceAI21/8/202630/9/2026
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py. Requests to /v1/chat/completions with a…
AnalizadaMedia (5.5)0.18%—Nvidia Triton Inference Server18/8/20261/9/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution.
AnalizadaAlta (7.5)0.67%—Nvidia Triton Inference Server18/8/20261/9/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.
AnalizadaAlta (7.5)0.67%—Nvidia Triton Inference Server18/8/20261/9/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.
AnalizadaCrítica (9.8)0.73%—Nvidia Triton Inference Server18/8/20262/9/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.
AnalizadaCrítica (9.1)0.74%—Nvidia Triton Inference Server18/8/20262/9/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.
AnalizadaMedia (5.4)0.16%—Intel Approximate Bayesian Inference Framework11/8/20262/10/2026
Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit #484c949 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This…
AnalizadaAlta (7.1)0.23%—Nvidia Triton Inference Server4/8/202617/8/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information…
AplazadaMedia (6.9)0.43%—Huggingface Text-generation-inferenceAI16/7/202616/7/2026
text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the server into issuing arbitrary HTTP GET requests by supplying a crafted image_url value in chat…
AplazadaAlta (7.5)0.49%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service.
AplazadaMedia (6.5)0.44%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
AplazadaAlta (7.5)0.49%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.5)0.49%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.5)0.53%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.5)0.53%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaAlta (7.5)0.54%—Nvidia Triton Inference Server14/7/20264/9/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaAlta (7.5)0.67%—Nvidia Triton Inference Server1/7/20266/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaAlta (7.5)0.72%—Nvidia Triton Inference Server1/7/20266/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaMedia (6.5)7.1%⚠ Explotación activaEncode StarletteRedhat AI Inference ServerRedhat Ansible Automation PlatformRedhat Migration Toolkit FOR Applications+426/5/20261/10/2026
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make…
AnalizadaAlta (7.5)0.41%—Nvidia Triton Inference Server20/5/202624/7/2026
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.