Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

326 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.88%—Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+468/7/202017/6/2026
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause…
ModificadaAlta (7.5)0.88%—Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+468/7/202017/6/2026
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause…
ModificadaAlta (7.5)0.88%—Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+468/7/202017/6/2026
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause…
ModificadaAlta (7.5)2.0%—Dell Vxrail D560f FirmwareDell Vxrail D560 Firmware6/7/202017/6/2026
Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.
ModificadaMedia (4.4)0.29%—Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 Firmware+35010/6/202017/6/2026
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default…
ModificadaMedia (6.7)0.33%—Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+1689/6/202017/6/2026
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
ModificadaMedia (6.8)0.28%—Lenovo Thinkpad 11E Yoga GEN 6 FirmwareLenovo Thinkpad 11E FirmwareLenovo Thinkpad Yoga 11E 3RD GEN FirmwareLenovo Thinkpad Yoga 11E 4TH GEN Firmware+969/6/202017/6/2026
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
ModificadaBaja (3.9)0.15%—Huawei Hege-560 FirmwareHuawei Hege-570 FirmwareHuawei Osca-550 FirmwareHuawei Osca-550a Firmware+220/3/202017/6/2026
There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to make malicious modifications.Affected product versions include:HEGE-560 versions 1.0.1.21(SP3);HEGE-570 versions…
ModificadaMedia (5.3)0.35%—Dell Chengming 3980 FirmwareDell G3 3579 FirmwareDell G3 3590 FirmwareDell G3 3779 Firmware+17021/2/202017/6/2026
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring…
ModificadaMedia (6.8)0.24%—Huawei Hege-560 FirmwareHuawei Osca-550 FirmwareHuawei Osca-550a FirmwareHuawei Osca-550ax Firmware+118/2/202017/6/2026
Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X version 1.0.0.71(SP2) have an insufficient authentication vulnerability. An attacker can access the device physically and perform specific operations to exploit this vulnerability. Successful exploitation…
ModificadaMedia (6.1)0.21%—Huawei Hege-560 FirmwareHuawei Osca-550 FirmwareHuawei Osca-550a FirmwareHuawei Osca-550ax Firmware+218/2/202017/6/2026
Huawei HEGE-570 version 1.0.1.22(SP3); and HEGE-560, OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X version 1.0.1.21(SP3) have an insufficient verification vulnerability. An attacker can access the device physically and exploit this vulnerability to tamper with device information. Successful exploit may cause service…
ModificadaMedia (6.8)0.23%—Huawei Hege-560 FirmwareHuawei Osca-550 FirmwareHuawei Osca-550a FirmwareHuawei Osca-550ax Firmware+118/2/202017/6/2026
Huawei HEGE-560 version 1.0.1.20(SP2), OSCA-550 version 1.0.0.71(SP1), OSCA-550A version 1.0.0.71(SP1), OSCA-550AX version 1.0.0.71(SP2), and OSCA-550X version 1.0.0.71(SP2) have an insufficient verification vulnerability. An attacker can perform specific operations to exploit this vulnerability by physical access…
ModificadaMedia (5.5)1.4%💥 PoCCanonical Ubuntu LinuxIntel Atom E3805Intel Atom E3815Intel Atom E3825+44117/1/202017/6/2026
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
ModificadaMedia (6.5)0.92%—Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+77414/11/201917/6/2026
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
ModificadaMedia (6.5)3.1%—Opensuse LeapFedoraproject FedoraSlackwareHP Apollo 4200 Firmware+15614/11/201917/6/2026
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
ModificadaAlta (7.8)0.67%—Redhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUSRedhat Enterprise Linux Server TUSIntel Graphics Driver+35314/11/201917/6/2026
Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series;…
ModificadaAlta (8.8)0.62%—Intel Wi-fi 6 Ax201 FirmwareIntel Wi-fi 6 Ax200 FirmwareIntel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 Firmware+914/11/201917/6/2026
Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via adjacent access.
ModificadaAlta (7.8)0.36%—Intel Wi-fi 6 Ax201 FirmwareIntel Wi-fi 6 Ax200 FirmwareIntel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 Firmware+914/11/201917/6/2026
Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via local access.
ModificadaCrítica (9.8)1.3%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
ModificadaMedia (6.4)0.33%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaMedia (6.4)0.35%—Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+38812/11/201917/6/2026
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
ModificadaMedia (6.5)0.32%—Cisco Aironet 1540 FirmwareCisco Aironet 1560 FirmwareCisco Aironet 1800 FirmwareCisco Aironet 2800 Firmware+116/10/201917/6/2026
A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an AP port to go into an error disabled state. The vulnerability occurs because BPDUs received from specific wireless clients are forwarded…
ModificadaMedia (6.5)0.46%—Cisco Aironet 1540 FirmwareCisco Aironet 1560 FirmwareCisco Aironet 1850 FirmwareCisco Aironet 2800 Firmware+316/10/201917/6/2026
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation of Cisco Aironet and Catalyst 9100 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. The…
ModificadaCrítica (9.8)3.0%—Cisco Aironet 1540 FirmwareCisco Aironet 1560 FirmwareCisco Aironet 1800 FirmwareCisco Aironet 2800 Firmware+216/10/201917/6/2026
A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain URLs on an affected device. An attacker could exploit this…
ModificadaMedia (6.5)1.2%—Lenovo Legion Y520t Z370 FirmwareLenovo Aio310-20iap FirmwareLenovo Aio510-22ish FirmwareLenovo Aio510-23ish Firmware+10429/8/201917/6/2026
There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at a higher privilege. The following are affected products and versions: Legion Y520T_Z370 6.0.1.8642, AIO310-20IAP 6.0.1.8642, AIO510-22ISH 6.0.1.8642, AIO510-23ISH…