Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.24% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.8) | 0.21% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.8) | 0.21% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Media (4.4) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (4.4) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Alta (7.8) | 0.21% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could potentially exploit this vulnerability by sending excess data to a function in order to gain arbitrary code execution on the system. | |
| Modificada | Media (5.1) | 0.16% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures. | |
| Modificada | Baja (2.4) | 0.23% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain an Improper Protection Against Voltage and Clock Glitches vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by triggering a fault condition in order to change the behavior of the system. | |
| Modificada | Baja (2.3) | 0.18% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by sending unexpected null bytes in order to read memory on the system. | |
| Modificada | Media (4.4) | 0.18% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by consuming excess memory in order to cause the application to crash. | |
| Modificada | Baja (2.3) | 0.18% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain an Information Exposure vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order access sensitive state information on the system. | |
| Modificada | Media (5.1) | 0.16% | — | Dell Chengming 3900 FirmwareDell Inspiron 14 Plus 7420 FirmwareDell Inspiron 16 Plus 7620 FirmwareDell Inspiron 3910 Firmware+21 | 12/9/2022 | 17/6/2026 | Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures. | |
| Modificada | Alta (7.8) | 0.22% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+395 | 6/9/2022 | 17/6/2026 | Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could exploit this vulnerability by sending malicious input via SMI to obtain arbitrary code execution during SMM. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+395 | 6/9/2022 | 17/6/2026 | Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI to bypass security checks resulting in arbitrary code execution in SMM. | |
| Modificada | Alta (7) | 0.14% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+395 | 6/9/2022 | 17/6/2026 | Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI in order to bypass security checks during SMM. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+395 | 6/9/2022 | 17/6/2026 | Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls. | |
| Modificada | Media (4.8) | 0.62% | — | Rich-web Coming Soon | 22/8/2022 | 17/6/2026 | The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Crítica (9.8) | 1.1% | — | Mingsoft Mcms | 16/8/2022 | 17/6/2026 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists. | |
| Modificada | Crítica (9.8) | 1.1% | — | Mingsoft Mcms | 16/8/2022 | 17/6/2026 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter. | |
| Modificada | Media (6.8) | 0.37% | — | Dell Chengming 3980 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G3 3579 Firmware+104 | 9/8/2022 | 17/6/2026 | Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system. | |
| Modificada | Media (6.5) | 0.52% | — | Themeisle WP Maintenance Mode & Coming Soon | 11/7/2022 | 17/6/2026 | The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack | |
| Modificada | Crítica (9) | 0.98% | — | Asus Zenwifi Xd4s FirmwareAsus Zenwifi XT9 FirmwareAsus Zenwifi XD5 FirmwareAsus Zenwifi PRO Et12 Firmware+89 | 5/7/2022 | 17/6/2026 | ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mingsoft Mcms | 1/7/2022 | 17/6/2026 | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability. | |
| Modificada | Media (6.1) | 0.79% | — | Site Offline OR Coming Soon Project Site Offline OR Coming Soon | 27/6/2022 | 17/6/2026 | The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its settings, and it also lacking sanitisation as well as escaping in some of them. As a result, attackers could make a logged in admin change them and put Cross-Site Scripting payloads in them via a CSRF… | |
| Modificada | Media (4.8) | 0.59% | — | Colorlib Coming Soon & Maintenance Mode | 20/6/2022 | 17/6/2026 | The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered_html is disallowed (for example in multisite setup) |