Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9) | 1.8% | — | AMD Ryzen Mobile FirmwareAMD Ryzen PRO FirmwareAMD Epyc Server FirmwareAMD Ryzen Firmware | 22/3/2018 | 17/6/2026 | The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTERKEY-1, MASTERKEY-2, and MASTERKEY-3. | |
| Modificada | Alta (7.8) | 0.38% | — | Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+144 | 18/8/2017 | 17/6/2026 | A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path. | |
| Modificada | Media (6.1) | 0.67% | — | Rspamd Project Rspamd | 29/7/2017 | 17/6/2026 | interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page. | |
| Modificada | Alta (7.8) | 0.57% | — | AMD Fglrx-driver | 7/6/2017 | 17/6/2026 | AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723. | |
| Modificada | Alta (7.8) | 0.57% | — | AMD Fglrx-driver | 7/6/2017 | 17/6/2026 | AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack. | |
| Modificada | Media (5.5) | 0.38% | — | AMD Ryzen | 25/3/2017 | 17/6/2026 | The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops test suite. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Media (4.4) | 0.30% | — | Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+70 | 30/11/2016 | 17/6/2026 | A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be… | |
| Modificada | Media (5.4) | 0.27% | — | Intsig Camdictionary | 21/10/2014 | 17/6/2026 | The CamDictionary (aka com.intsig.camdict) application 2.3.0.20131118 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.7) | 0.59% | — | AMD 16H Model Processor FirmwareAMD 16H Model 00H ProcessorAMD 16H Model 0FH Processor | 29/11/2013 | 17/6/2026 | The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue. | |
| Modificada | Alta (7.5) | 4.6% | — | Spamdyke | 19/6/2012 | 16/6/2026 | Multiple buffer overflows in Spamdyke before 4.3.0 might allow remote attackers to execute arbitrary code via vectors related to "serious errors in the usage of snprintf()/vsnprintf()" in which the return values may be larger than the size of the buffer. | |
| Modificada | Media (6.4) | 1.4% | — | Spamdyke | 19/6/2008 | 16/6/2026 | The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed by arbitrary RCPT commands and a second… | |
| Modificada | Media (6.9) | 0.29% | — | AMD Catalyst DriverATI Catalyst Driver | 13/8/2007 | 16/6/2026 | The AMD ATI atidsmxx.sys 3.0.502.0 driver on Windows Vista allows local users to bypass the driver signing policy, write to arbitrary kernel memory locations, and thereby gain privileges via unspecified vectors, as demonstrated by "Purple Pill". | |
| Modificada | Media (4.6) | 0.36% | — | Scramdisk 4 Linux | 18/4/2007 | 16/6/2026 | Certain programs in containers in ScramDisk 4 Linux before 1.0-1 execute with SUID permissions, which allows local users to gain privileges via mounted containers. | |
| Modificada | Media (6.9) | 0.34% | — | Scramdisk 4 Linux | 18/4/2007 | 16/6/2026 | ScramDisk 4 Linux before 1.0-1 does not perform permission checks on mount points, which allows local users to gain privileges by using a system directory as a mount point for a container. | |
| Modificada | Alta (7.5) | 5.8% | 💥 Exploit | Reamday Enterprises Magic News Plus | 2/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the php_script_path parameter. NOTE: This issue may overlap CVE-2006-0723. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Reamday Enterprises Magic News Plus | 2/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php. | |
| Modificada | Alta (7.5) | 8.6% | 💥 Exploit | Reamday Enterprises Magic News PRO | 15/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter. | |
| Modificada | Baja (2.6) | 1.5% | — | Reamday Enterprises Magic Downloads | 16/2/2006 | 16/6/2026 | settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not… | |
| Modificada | Baja (2.6) | 1.6% | — | Reamday Enterprises Magic News Lite | 16/2/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter. | |
| Modificada | Baja (2.6) | 1.3% | — | Reamday Enterprises Magic News Lite | 16/2/2006 | 16/6/2026 | profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not… | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Reamday Enterprises Magic Calendar Lite | 13/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) $total_login and (2) $total_password parameter. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Reamday Enterprises Magic News Plus | 10/1/2006 | 16/6/2026 | settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters. |