Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 1.1% | — | Lenovo Nextscale N1200 Enclosure FirmwareLenovo Thinkagile Cp-cb-10 FirmwareLenovo Thinkagile Cp-cb-10e FirmwareLenovo Thinkagile HX Enclosure Firmware+64 | 15/4/2024 | 17/6/2026 | A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function. | |
| Analizada | Media (4.4) | 0.18% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+264 | 10/4/2024 | 17/6/2026 | Dell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Alta (7.8) | 0.15% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+89 | 3/4/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation. | |
| Analizada | Baja (3.3) | 0.17% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+120 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory. | |
| Analizada | Media (6.3) | 0.11% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+54 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources. | |
| Analizada | Alta (8.8) | 0.15% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+54 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to out-of-bound read/writes to SMRAM. | |
| Analizada | Baja (3.3) | 0.20% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+120 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory. | |
| Analizada | Alta (8.4) | 0.20% | — | Dell Poweredge T360 FirmwareDell Poweredge R360 FirmwareDell Poweredge R650 FirmwareDell Poweredge R750 Firmware+82 | 13/3/2024 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM. | |
| Analizada | Media (4.9) | 0.49% | — | Dell Precision 3430 Tower FirmwareDell Precision 3431 Tower FirmwareDell Precision 3630 Tower FirmwareDell Precision 5820 Tower Firmware+169 | 1/3/2024 | 17/6/2026 | Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function. | |
| Modificada | Media (4.4) | 0.16% | — | Dell Optiplex 3000 Micro FirmwareDell Optiplex 3000 Small Form Factor FirmwareDell Optiplex 3000 Tower FirmwareDell Optiplex 5000 Micro Firmware+287 | 6/2/2024 | 17/6/2026 | Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Media (6.5) | 1.2% | — | Khronos OpenclKhronos VulkanImaginationtech DDKAMD Instinct Mi300x Firmware+128 | 16/1/2024 | 17/6/2026 | A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures. | |
| Modificada | Alta (7.5) | 0.64% | — | Hitachienergy Rtu520 FirmwareHitachienergy Rtu530 FirmwareHitachienergy Rtu540 FirmwareHitachienergy Rtu560 Firmware | 4/1/2024 | 17/6/2026 | A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500 in a high rate, causing the targeted RTU500 CMU to reboot. The… | |
| Analizada | Media (6.1) | 0.41% | — | Hitachienergy Rtu520 FirmwareHitachienergy Rtu530 FirmwareHitachienergy Rtu540 FirmwareHitachienergy Rtu560 Firmware | 14/12/2023 | 17/6/2026 | A vulnerability exists in the webserver that affects the RTU500 series product versions listed below. A malicious actor could perform cross-site scripting on the webserver due to user input being improperly sanitized. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+122 | 8/12/2023 | 17/6/2026 | Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation. | |
| Modificada | Media (6.1) | 0.41% | — | Hitachienergy Rtu520 FirmwareHitachienergy Rtu530 FirmwareHitachienergy Rtu540 FirmwareHitachienergy Rtu560 Firmware | 4/12/2023 | 17/6/2026 | A vulnerability exists in the HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Incomplete or wrong received APDU frame layout may cause blocking on link layer. Error reason was an endless blocking when reading incoming frames on link layer with wrong length information of APDU or… | |
| Modificada | Media (6.1) | 0.39% | — | Hitachienergy Rtu520 FirmwareHitachienergy Rtu530 FirmwareHitachienergy Rtu540 FirmwareHitachienergy Rtu560 Firmware | 4/12/2023 | 17/6/2026 | A vulnerability exists in the webserver that affects the RTU500 series product versions listed below. A malicious actor could perform cross-site scripting on the webserver due to an RDT language file being improperly sanitized. | |
| Modificada | Alta (8) | 0.40% | — | Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+625 | 14/11/2023 | 17/6/2026 | Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Alta (7.8) | 1.7% | — | Intel Core I3-10100y FirmwareIntel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 Firmware+219 | 14/11/2023 | 17/6/2026 | Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access. | |
| Modificada | Baja (3.5) | 0.30% | — | Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+625 | 14/11/2023 | 17/6/2026 | Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Crítica (9.8) | 13% | — | Zavio Cf7500 FirmwareZavio Cf7300 FirmwareZavio Cf7201 FirmwareZavio Cf7501 Firmware+7 | 8/11/2023 | 17/6/2026 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 has a command injection vulnerability in their implementation of their binaries and handling of network requests. | |
| Modificada | Crítica (9.8) | 1.3% | — | Zavio Cf7500 FirmwareZavio Cf7300 FirmwareZavio Cf7201 FirmwareZavio Cf7501 Firmware+7 | 8/11/2023 | 17/6/2026 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While parsing certain XML elements from incoming network requests, the product does not sufficiently check or validate… | |
| Modificada | Crítica (9.8) | 1.3% | — | Zavio Cf7500 FirmwareZavio Cf7300 FirmwareZavio Cf7201 FirmwareZavio Cf7501 Firmware+7 | 8/11/2023 | 17/6/2026 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. During the processing and parsing of certain fields in XML elements from incoming network requests, the product does… | |
| Modificada | Crítica (9.8) | 49% | — | Zavio Cf7500 FirmwareZavio Cf7300 FirmwareZavio Cf7201 FirmwareZavio Cf7501 Firmware+7 | 8/11/2023 | 17/6/2026 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate… | |
| Modificada | Crítica (9.8) | 1.2% | — | Zavio Cf7500 FirmwareZavio Cf7300 FirmwareZavio Cf7201 FirmwareZavio Cf7501 Firmware+7 | 8/11/2023 | 17/6/2026 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to stack-based overflows. During the process of updating certain settings sent from incoming network requests, the product does not sufficiently check or validate… | |
| Modificada | Alta (8.8) | 0.52% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile Hx1331 Firmware+119 | 25/10/2023 | 17/6/2026 | An authenticated XCC user can change permissions for any user through a crafted API command. |