Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3834 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.6) | 0.12% | — | Intel TDX ModuleAI | 10/2/2026 | 17/6/2026 | Out-of-bounds read for some TDX before version tdx module 1.5.24 within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are… | |
| Analizada | Media (6) | 0.26% | — | Intel Ethernet Controller | 10/2/2026 | 17/6/2026 | Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, cpk 1.3.7 within Ring 0: Bare Metal OS may allow a denial of service. Network adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may… | |
| Aplazada | Media (5.6) | 0.08% | — | Intel TDX ModuleAI | 10/2/2026 | 17/6/2026 | Race condition for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present… | |
| Aplazada | Media (5.4) | 0.09% | — | Intel Battery Life Diagnostic ToolAI | 10/2/2026 | 17/6/2026 | Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Aplazada | Baja (1.8) | 0.14% | — | Intel ProcessorAI | 10/2/2026 | 17/6/2026 | Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack… | |
| Aplazada | Alta (8.3) | 0.13% | — | Intel TDX ModuleAI | 10/2/2026 | 17/6/2026 | Race condition for some TDX Module within Ring 0: Hypervisor may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present with… | |
| Aplazada | Media (6.8) | 0.10% | — | Intel Quick Assist TechnologyAI | 10/2/2026 | 17/6/2026 | Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… | |
| Aplazada | Media (5.6) | 0.10% | — | Intel TDX ModuleAI | 10/2/2026 | 17/6/2026 | Out-of-bounds read for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Software side channel adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements… | |
| Aplazada | Media (5.6) | 0.10% | — | Intel Converged Security AND Management Engine FirmwareAI | 10/2/2026 | 17/6/2026 | Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially… | |
| Aplazada | Media (5.6) | 0.11% | — | Intel TDXAI | 10/2/2026 | 17/6/2026 | Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack… | |
| Aplazada | Media (6.7) | 0.12% | — | Intel PlatformAI | 10/2/2026 | 17/6/2026 | Loop with unreachable exit condition ('infinite loop') for some Intel(R) Platform within Ring 0: Kernel may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack… | |
| Analizada | Media (5.6) | 0.10% | — | Intel Ethernet Controller | 10/2/2026 | 17/6/2026 | Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before version NVM ver. 3.84 within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a high complexity attack may enable denial of service.… | |
| Analizada | Media (6.7) | 0.12% | — | Intel Ethernet Controller | 10/2/2026 | 17/6/2026 | Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur… | |
| Aplazada | Alta (7.1) | 0.12% | — | Intel Server Firmware Update UtilityAI | 10/2/2026 | 17/6/2026 | Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Baja (2) | 0.11% | — | Vmware EsxiAIIntel Ethernet 800 SeriesAI | 10/2/2026 | 17/6/2026 | Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack… | |
| Analizada | Media (6.7) | 0.12% | — | Intel Ethernet Controller | 10/2/2026 | 17/6/2026 | Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Media (5.7) | 0.14% | — | Intel TDX ModuleAI | 10/2/2026 | 17/6/2026 | Improper buffer restrictions in the firmware for the TDX Module may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present… | |
| Aplazada | Media (5.4) | 0.12% | — | Intel Optane Pmem Management SoftwareAI | 10/2/2026 | 17/6/2026 | Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584, CR_MGMT_02.00.00.4052, CR_MGMT_03.00.00.0538 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high… | |
| Aplazada | Media (5.4) | 0.14% | — | Intel Vtune ProfilerAIIntel Oneapi Base ToolkitAI | 10/2/2026 | 17/6/2026 | Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolkits before version 2025.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable… | |
| Aplazada | Alta (8.2) | 0.24% | — | Intel AMTAIIntel Standard ManageabilityAI | 10/2/2026 | 17/6/2026 | Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel may allow a denial of service. Network adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via network… | |
| Aplazada | Media (5.4) | 0.10% | — | Intel Optane Pmem Management SoftwareAI | 10/2/2026 | 17/6/2026 | Improper conditions check for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_02.00.00.4052, CR_MGMT_03.00.00.0538 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable… | |
| Analizada | Media (6.5) | 0.36% | — | SAP Businessobjects Business Intelligence Platform | 10/2/2026 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of… | |
| Analizada | Alta (8.1) | 0.30% | — | SAP Businessobjects Business Intelligence Platform | 10/2/2026 | 17/6/2026 | The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim may click on this malicious URL, resulting in an unvalidated redirect to the attacker-controlled domain and subsequently… | |
| Analizada | Alta (7.5) | 0.38% | — | SAP Businessobjects Business Intelligence Platform | 10/2/2026 | 17/6/2026 | SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authentication, which prevents the legitimate users from accessing the platform. As a result, it has a high impact on the availability but no impact on the confidentiality and… | |
| Analizada | Alta (7.5) | 0.42% | — | SAP Businessobjects Business Intelligence Platform | 10/2/2026 | 17/6/2026 | SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repeatedly submitting these requests, the attacker could induce a persistent service disruption, rendering the CMS completely… |