Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.41% | — | Zenhive MPPAI | 22/9/2026 | 22/9/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats a voucher whose cumulativeAmount equals the channel's already-accepted cumulative… | |
| Aplazada | Alta (8.2) | 0.57% | — | Zenhive MPPAI | 22/9/2026 | 22/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that… | |
| Pendiente de análisis | Media (6.3) | 0.52% | — | Zenhive MPPAI | 16/9/2026 | 16/9/2026 | Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid. MPP.Plug.verify_credential in lib/mpp/plug.ex sets payment-receipt and cache-control: private on the connection before the wrapped application runs, and registers no… | |
| Pendiente de análisis | Media (6.3) | 0.52% | — | Zenhive MPPAI | 16/9/2026 | 16/9/2026 | Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Tempo duplicate-submission gate twice with one signed transaction. MPP.Methods.Tempo reserves the pre-broadcast dedup slot on the caller-supplied hex in reserve_hash_atomic/2, keyed through store_key/1… | |
| Aplazada | Alta (8.3) | 0.52% | — | Zenhive MPPAI | 6/9/2026 | 8/9/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account. When the server sponsors Tempo payments,… | |
| Aplazada | Alta (8.3) | 0.52% | — | Zenhive MPPAI | 6/9/2026 | 8/9/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing. When the server sponsors Tempo payments,… | |
| Analizada | Media (6.3) | 0.32% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.verify/2 guards against replay with a non-atomic check-then-mark sequence:… | |
| Analizada | Alta (8.3) | 0.59% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Methods.Tempo.FeePayerPolicy enforces its ceilings (max_gas, max_fee_per_gas,… | |
| Analizada | Alta (8.2) | 0.60% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. MPP.Methods.Tempo normally binds a settled TIP-20 TransferWithMemo to the specific challenge under verification through an attribution nonce… | |
| Analizada | Alta (8.7) | 0.60% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and amount (ERC-20) or to and value (native).… | |
| Aplazada | Alta (8.3) | 0.52% | — | Zenhive MPPAI | 17/7/2026 | 17/7/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3… | |
| Aplazada | Alta (8.3) | 0.52% | — | Zenhive MPPAI | 17/7/2026 | 17/7/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, degrading the sponsor's operating margin. When the mpp Elixir library is configured as fee payer (fee_payer: true),… | |
| Aplazada | Alta (8.2) | 0.63% | — | Zenhive MPPAI | 17/7/2026 | 17/7/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. When the mpp Elixir library is configured as fee payer (fee_payer: true), the MPP.Methods.Tempo payment method co-signs and… |