Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.76%—Dbbroadcast Mozart Next 100 FirmwareDbbroadcast Mozart Next 1000 FirmwareDbbroadcast Mozart Next 2000 FirmwareDbbroadcast Mozart Next 30 Firmware+1818/11/202517/6/2026
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endpoint. An attacker can exploit this by sending a crafted POST request with a malicious file (e.g., a PHP webshell) to the server. The uploaded file is stored in…
AnalizadaAlta (7.2)0.57%—Dbbroadcast Mozart Next 100 FirmwareDbbroadcast Mozart Next 1000 FirmwareDbbroadcast Mozart Next 2000 FirmwareDbbroadcast Mozart Next 30 Firmware+1818/11/202517/6/2026
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials can upload arbitrary files (e.g., PHP webshells), which are stored in the /patch/ directory. This allows the attacker…
AnalizadaMedia (6.7)0.17%—Dell Latitude 3140 2in1 FirmwareDell Latitude 3320 FirmwareDell Latitude 3330 FirmwareDell Latitude 3340 Firmware+2579/4/202517/6/2026
Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
AnalizadaAlta (8.2)0.17%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+38819/2/202517/6/2026
Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
ModificadaAlta (7.5)0.43%—Fujitsu Ipcom VE2 LS 100 FirmwareFujitsu Ipcom VE2 LS 200 FirmwareFujitsu Ipcom VE2 LS 220 FirmwareFujitsu Ipcom VE2 LS Plus 100 Firmware+154/9/202417/6/2026
Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. If this vulnerability is exploited, some of the encrypted communication may be decrypted by an attacker who can…
AnalizadaAlta (7.3)0.17%—Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+34228/8/202417/6/2026
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
ModificadaMedia (6.7)0.15%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+3842/7/202417/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
ModificadaMedia (6.8)0.25%—Dell XPS 17 9700 FirmwareDell XPS 15 9500 FirmwareDell Vostro 7500 FirmwareDell Precision 5750 Firmware+1112/6/202417/6/2026
Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.
AnalizadaMedia (6.5)16%⚠ Explotación activaTp-link Tl-wr841n FirmwareTp-link Mr6400 FirmwareTp-link Tl-wdr3600 FirmwareTp-link Tl-wdr4300 Firmware+323/5/20243/9/2026
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw…
AnalizadaMedia (4.4)0.18%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+26410/4/202417/6/2026
Dell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.
ModificadaMedia (4.4)0.16%—Dell Optiplex 3000 Micro FirmwareDell Optiplex 3000 Small Form Factor FirmwareDell Optiplex 3000 Tower FirmwareDell Optiplex 5000 Micro Firmware+2876/2/202417/6/2026
Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.
ModificadaMedia (6.1)0.31%—Fireeye EX 5500 FirmwareaFireeye EX 8500 FirmwareFireeye EX 3500 Firmware15/1/202417/6/2026
Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' and 's_f_name' parameters to an authenticated user to retrieve their session details.
ModificadaAlta (8)0.40%—Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+62514/11/202317/6/2026
Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
ModificadaBaja (3.5)0.30%—Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+62514/11/202317/6/2026
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
ModificadaAlta (7.5)0.50%—AMD Epyc 7232p FirmwareAMD Epyc 7252 FirmwareAMD Epyc 7262 FirmwareAMD Epyc 7272 Firmware+8114/11/202317/6/2026
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
ModificadaCrítica (9.8)0.99%—AMD Ryzen 9 3900 FirmwareAMD Ryzen 9 3900x FirmwareAMD Ryzen 9 3900xt FirmwareAMD Ryzen 9 3950x Firmware+10414/11/202317/6/2026
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
ModificadaCrítica (9.8)0.70%—AMD Ryzen 9 3900 FirmwareAMD Ryzen 9 3900x FirmwareAMD Ryzen 9 3900xt FirmwareAMD Ryzen 9 3950x Firmware+10114/11/202317/6/2026
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
ModificadaAlta (7.5)0.51%—AMD Epyc 7001 FirmwareAMD Epyc 7251 FirmwareAMD Epyc 7261 FirmwareAMD Epyc 7281 Firmware+13314/11/202317/6/2026
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
ModificadaMedia (5.5)0.18%—AMD Ryzen 3 3100 FirmwareAMD Ryzen 3 3200g FirmwareAMD Ryzen 3 3200ge FirmwareAMD Ryzen 3 3200u Firmware+9720/9/202317/6/2026
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
ModificadaMedia (4.4)0.19%—AMD Epyc 7003 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p Firmware+12120/9/202317/6/2026
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
ModificadaBaja (3.9)0.24%—Dell Alienware M15 R7 FirmwareDell Alienware M16 FirmwareDell Alienware M18 FirmwareDell Chengming 3900 Firmware+10716/8/202317/6/2026
Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may potentially exploit this vulnerability in order to modify a security-critical UEFI variable without knowledge of the BIOS administrator.
ModificadaMedia (6.3)0.19%—Dell Alienware M15 R7 FirmwareDell Alienware M16 FirmwareDell Alienware M18 FirmwareDell Chengming 3900 Firmware+23816/8/202317/6/2026
Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system.
ModificadaMedia (6.8)0.58%—AMD Ryzen 5 PRO 3400g FirmwareAMD Ryzen 5 3400g FirmwareAMD Ryzen 5 PRO 3400ge FirmwareAMD Ryzen 5 PRO 3350g Firmware+1188/8/202317/6/2026
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution.
ModificadaMedia (6.5)0.68%—Netgear Dgn3500 Firmware7/8/202317/6/2026
Netgear DGN3500 1.1.00.37 was discovered to contain a buffer overflow via the http_password parameter at setup.cgi.
ModificadaMedia (5.5)5.2%💥 PoCXENDebian LinuxAMD Ryzen 3 3100 FirmwareAMD Ryzen 3 3300x Firmware+6724/7/202317/6/2026
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.