Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9)1.8%—AMD Ryzen Mobile FirmwareAMD Ryzen PRO FirmwareAMD Epyc Server FirmwareAMD Ryzen Firmware22/3/201817/6/2026
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTERKEY-1, MASTERKEY-2, and MASTERKEY-3.
ModificadaAlta (7.8)0.38%—Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+14418/8/201717/6/2026
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.
ModificadaMedia (6.1)0.67%—Rspamd Project Rspamd29/7/201717/6/2026
interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.
ModificadaAlta (7.8)0.57%—AMD Fglrx-driver7/6/201717/6/2026
AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723.
ModificadaAlta (7.8)0.57%—AMD Fglrx-driver7/6/201717/6/2026
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
ModificadaMedia (5.5)0.38%—AMD Ryzen25/3/201717/6/2026
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops test suite.
ModificadaAlta (7.5)1.6%—Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+1627/2/201717/6/2026
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
ModificadaAlta (7.5)1.6%—Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+1627/2/201717/6/2026
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
ModificadaAlta (7.5)1.6%—Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+1627/2/201717/6/2026
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
ModificadaMedia (4.4)0.30%—Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+7030/11/201617/6/2026
A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be…
ModificadaMedia (5.4)0.27%—Intsig Camdictionary21/10/201417/6/2026
The CamDictionary (aka com.intsig.camdict) application 2.3.0.20131118 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.7)0.59%—AMD 16H Model Processor FirmwareAMD 16H Model 00H ProcessorAMD 16H Model 0FH Processor29/11/201317/6/2026
The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue.
ModificadaAlta (7.5)4.6%—Spamdyke19/6/201216/6/2026
Multiple buffer overflows in Spamdyke before 4.3.0 might allow remote attackers to execute arbitrary code via vectors related to "serious errors in the usage of snprintf()/vsnprintf()" in which the return values may be larger than the size of the buffer.
ModificadaMedia (6.4)1.4%—Spamdyke19/6/200816/6/2026
The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed by arbitrary RCPT commands and a second…
ModificadaMedia (6.9)0.29%—AMD Catalyst DriverATI Catalyst Driver13/8/200716/6/2026
The AMD ATI atidsmxx.sys 3.0.502.0 driver on Windows Vista allows local users to bypass the driver signing policy, write to arbitrary kernel memory locations, and thereby gain privileges via unspecified vectors, as demonstrated by "Purple Pill".
ModificadaMedia (4.6)0.36%—Scramdisk 4 Linux18/4/200716/6/2026
Certain programs in containers in ScramDisk 4 Linux before 1.0-1 execute with SUID permissions, which allows local users to gain privileges via mounted containers.
ModificadaMedia (6.9)0.34%—Scramdisk 4 Linux18/4/200716/6/2026
ScramDisk 4 Linux before 1.0-1 does not perform permission checks on mount points, which allows local users to gain privileges by using a system directory as a mount point for a container.
ModificadaAlta (7.5)5.8%💥 ExploitReamday Enterprises Magic News Plus2/3/200716/6/2026
PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the php_script_path parameter. NOTE: This issue may overlap CVE-2006-0723.
ModificadaMedia (4.3)1.6%💥 ExploitReamday Enterprises Magic News Plus2/3/200716/6/2026
Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.
ModificadaAlta (7.5)8.6%💥 ExploitReamday Enterprises Magic News PRO15/9/200616/6/2026
PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter.
ModificadaBaja (2.6)1.5%—Reamday Enterprises Magic Downloads16/2/200616/6/2026
settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not…
ModificadaBaja (2.6)1.6%—Reamday Enterprises Magic News Lite16/2/200616/6/2026
PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter.
ModificadaBaja (2.6)1.3%—Reamday Enterprises Magic News Lite16/2/200616/6/2026
profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not…
ModificadaAlta (7.5)2.1%💥 ExploitReamday Enterprises Magic Calendar Lite13/2/200616/6/2026
Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) $total_login and (2) $total_password parameter.
ModificadaMedia (5)2.3%💥 ExploitReamday Enterprises Magic News Plus10/1/200616/6/2026
settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.