Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.40% | — | AMD Ryzen 5300g FirmwareAMD Ryzen 5300ge FirmwareAMD Ryzen 5500 FirmwareAMD Ryzen 5600 Firmware+51 | 9/5/2023 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event potentially leading to a denial of service. | |
| Modificada | Alta (8.8) | 0.77% | — | AMD Ryzen 6600h FirmwareAMD Ryzen 6600hs FirmwareAMD Ryzen 6600u FirmwareAMD Ryzen 6800h Firmware+59 | 9/5/2023 | 17/6/2026 | Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Ryzen 6600h FirmwareAMD Ryzen 6600hs FirmwareAMD Ryzen 6600u FirmwareAMD Ryzen 6800h Firmware+40 | 9/5/2023 | 17/6/2026 | Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service. | |
| Modificada | Media (6.1) | 0.28% | — | AMD Ryzen 5300g FirmwareAMD Ryzen 5300ge FirmwareAMD Ryzen 5500 FirmwareAMD Ryzen 5600 Firmware+52 | 9/5/2023 | 17/6/2026 | Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure Processor) bootloader accessible memory to a serial port, resulting in a potential loss of integrity. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Ryzen 5500 FirmwareAMD Ryzen 5600 FirmwareAMD Ryzen 5600g FirmwareAMD Ryzen 5600x Firmware+19 | 9/5/2023 | 17/6/2026 | Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service. | |
| Modificada | Crítica (9.1) | 0.56% | — | AMD Ryzen 5300g FirmwareAMD Ryzen 5300ge FirmwareAMD Ryzen 5500 FirmwareAMD Ryzen 5600 Firmware+52 | 9/5/2023 | 17/6/2026 | Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity. | |
| Modificada | Crítica (9.1) | 0.56% | — | AMD Ryzen 6600h FirmwareAMD Ryzen 6600hs FirmwareAMD Ryzen 6600u FirmwareAMD Ryzen 6800h Firmware+62 | 9/5/2023 | 17/6/2026 | Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and integrity. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Ryzen 5300g FirmwareAMD Ryzen 5300ge FirmwareAMD Ryzen 5500 FirmwareAMD Ryzen 5600 Firmware+52 | 9/5/2023 | 17/6/2026 | Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service. | |
| Modificada | Media (5.5) | 0.19% | — | AMD Epyc 7773x FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 Firmware+124 | 9/5/2023 | 17/6/2026 | A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure. | |
| Modificada | Alta (7.4) | 0.40% | — | AMD Epyc 7001 FirmwareAMD Epyc 7251 FirmwareAMD Epyc 7261 FirmwareAMD Epyc 7281 Firmware+94 | 9/5/2023 | 17/6/2026 | A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure. | |
| Modificada | Media (5.5) | 0.18% | — | AMD Epyc 7773x FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 Firmware+148 | 9/5/2023 | 17/6/2026 | Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+185 | 2/5/2023 | 17/6/2026 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Wcn3998 Firmware+64 | 2/5/2023 | 17/6/2026 | Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Ar8035 FirmwareQualcomm Wcn3998 FirmwareQualcomm Wcn6750 Firmware+64 | 2/5/2023 | 17/6/2026 | Transient DOS due to reachable assertion in Modem during OSI decode scheduling. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+77 | 2/5/2023 | 17/6/2026 | Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH. | |
| Modificada | Media (5.5) | 0.18% | — | HP Elite Dragonfly G3 FirmwareHP Dragonfly Folio G3 FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX Firmware+87 | 28/4/2023 | 17/6/2026 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.8) | 0.81% | — | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO | 26/4/2023 | 17/6/2026 | Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to… | |
| Modificada | Alta (7.8) | 0.42% | — | 360 Total Security | 19/4/2023 | 17/6/2026 | Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: This is a set of vulnerabilities affecting popular software, "360… | |
| Modificada | Crítica (10) | 3.1% | — | Browser.360 Chrome | 19/4/2023 | 17/6/2026 | Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges. | |
| Modificada | Crítica (10) | 1.4% | — | Browser.360 Safe Browser | 19/4/2023 | 17/6/2026 | Buffer Overflow vulnerability in Qihoo 360 Total Security v10.8.0.1060 and v10.8.0.1213 allows attacker to escalate privileges. | |
| Modificada | Alta (8.8) | 1.0% | — | 360 Total Security | 19/4/2023 | 17/6/2026 | Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Chrome (https://browser.360.cn/ee/) is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: This is a set of vulnerabilities affecting popular software, and the installation packages… | |
| Modificada | Alta (7.8) | 0.40% | — | 360totalsecurity 360 Total Security | 19/4/2023 | 17/6/2026 | Buffer Overflow vulnerability in Qihoo 360 Safe guard v12.1.0.1004, v12.1.0.1005, v13.1.0.1001 allows attacker to escalate priveleges. | |
| Modificada | Crítica (10) | 1.3% | — | Browser.360 Safe Browser | 19/4/2023 | 17/6/2026 | Buffer Overflow vulnerability in Qihoo 360 Safe Browser v13.0.2170.0 allows attacker to escalate priveleges. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8016 FirmwareQualcomm Apq8017 Firmware+349 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+221 | 13/4/2023 | 17/6/2026 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. |