Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3834 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.10% | — | Intel Uefi ImcerrorhandlerAI | 10/3/2026 | 17/6/2026 | Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when… | |
| Pendiente de análisis | Alta (8.7) | 0.11% | — | Intel Uefi FlashucacmsmmAI | 10/3/2026 | 17/6/2026 | Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Alta (7.1) | 0.08% | — | Intel Wheaerst SMM ModuleAI | 10/3/2026 | 17/6/2026 | Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access… | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | Intel Uefi Wheaerst ModuleAI | 10/3/2026 | 17/6/2026 | Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Media (5.7) | 0.10% | — | Intel Uefi FirmwareAI | 10/3/2026 | 17/6/2026 | Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable data manipulation. This result may potentially occur via local access when attack… | |
| Analizada | Alta (7.8) | 0.18% | — | Dell Command | Intel Vpro OUT OF Band | 3/3/2026 | 17/6/2026 | Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | |
| Analizada | Baja (2.7) | 0.66% | — | Naturalintelligence Fast-xml-parser | 26/2/2026 | 17/6/2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use… | |
| Analizada | Baja (2.1) | 6.6% | — | Intelbras TIP 635g Firmware | 24/2/2026 | 17/6/2026 | A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping Handler. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this… | |
| Modificada | Crítica (9.3) | 0.50% | — | Naturalintelligence Fast-xml-parser | 20/2/2026 | 10/9/2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities… | |
| Modificada | Alta (7.5) | 0.97% | — | Naturalintelligence Fast-xml-parser | 19/2/2026 | 10/9/2026 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser… | |
| Aplazada | Crítica (9.2) | 0.77% | — | Intelbras VIP 3260 Z IAAI | 16/2/2026 | 17/6/2026 | A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The… | |
| Aplazada | Media (5.4) | 0.09% | — | Intel Chipset SoftwareAI | 10/2/2026 | 17/6/2026 | Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result… | |
| Aplazada | Media (5.4) | 0.12% | — | Intel Memory AND Storage ToolAI | 10/2/2026 | 17/6/2026 | Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially… | |
| Aplazada | Media (5.4) | 0.16% | — | Intel System Firmware Update UtilityAI | 10/2/2026 | 17/6/2026 | Incorrect permission assignment for critical resource for some System Firmware Update Utility (SysFwUpdt) for Intel(R) Server Boards and Intel(R) Server Systems Based before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined… | |
| Aplazada | Alta (7) | 0.16% | — | Intel Quick Assist TechnologyAI | 10/2/2026 | 15/7/2026 | Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This… | |
| Aplazada | Media (5.7) | 0.09% | — | Intel NPU DriversAI | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Aplazada | Baja (2) | 0.15% | — | Intel NPU DriverAI | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data corruption. This result may potentially occur via local access… | |
| Analizada | Baja (2) | 0.09% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Media (6.8) | 0.10% | — | Intel NPU DriverAI | 10/2/2026 | 17/6/2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Aplazada | Media (5.6) | 0.10% | — | Intel TDX ModuleAI | 10/2/2026 | 17/6/2026 | Use of uninitialized variable for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements… | |
| Analizada | Media (5.4) | 0.12% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Analizada | Media (5.4) | 0.12% | — | Intel Graphics DriverIntel Graphics SoftwareLinux Intel LTS Kernel | 10/2/2026 | 17/6/2026 | Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Alta (8.7) | 0.29% | — | Intel AMTAIIntel Standard ManageabilityAI | 10/2/2026 | 17/6/2026 | Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applications may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network… |