Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

77 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)0.23%—Lenovo Bladecenter Hs23 FirmwareLenovo Bladecenter Hs23e FirmwareLenovo Compute Node-x440 FirmwareLenovo Flex System X220 Firmware+1414/10/202017/6/2026
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
ModificadaMedia (6.1)0.67%—IBM Bladecenter Advanced Management Module Firmware15/9/202017/6/2026
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenticated user's AMM credentials to be disclosed if the user is convinced to visit a malicious web…
ModificadaCrítica (9.8)1.2%—Bladex Springblade30/7/202017/6/2026
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
ModificadaCrítica (9)1.1%—HP Blade Maintenance EntityHP Integrated Maintenance EntityHP Maintenance Entity24/4/202017/6/2026
This document describes a security vulnerability in Blade Maintenance Entity, Integrated Maintenance Entity and Maintenance Entity products. All J/H-series NonStop systems have a security vulnerability associated with an open UDP port 17185 on the Maintenance LAN which could result in information disclosure,…
ModificadaAlta (8.1)1.7%—Blade-group Shadow14/11/201917/6/2026
The network protocol of Blade Shadow though 2.13.3 allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victim's IP address, because packet data can be injected into the unencrypted UDP packet stream.
ModificadaAlta (8.2)0.38%—Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+28014/11/201917/6/2026
Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of…
ModificadaMedia (6.7)0.38%—Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+28014/11/201917/6/2026
Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local…
ModificadaMedia (6.1)1.1%—Lenovo Bladecenter Hs22 FirmwareLenovo Bladecenter Hs22v FirmwareLenovo Bladecenter HX5 FirmwareLenovo System X Idataplex Dx360 M2 Firmware+1119/8/201917/6/2026
A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could allow an unauthenticated user to cause JavaScript code to be stored in the IMM log which may then be executed in the…
ModificadaMedia (5.1)0.29%—HP Blade Maintenance EntityHP Integrated Maintenance EntityHP Maintenance Entity5/6/201917/6/2026
The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system layout and configuration.
ModificadaAlta (7.5)1.3%—Lenovo Flex System X240 M4 FirmwareLenovo Flex System X240 M5 FirmwareLenovo Flex System X280 X6 FirmwareLenovo Flex System X440 M4 Firmware+3822/4/201917/6/2026
In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support.
ModificadaAlta (7.5)0.77%—IBM Bladecenter Hs23 FirmwareIBM System X3530 M4 FirmwareIBM System X3630 M4 FirmwareIBM System X3650 M4 HD Firmware22/4/201917/6/2026
A potential vulnerability was found in an SMI handler in various BIOS versions of certain legacy IBM System x and IBM BladeCenter systems that could lead to denial of service.
ModificadaMedia (4.7)0.41%—Zteusa ZTE Blade Vantage FirmwareZteusa ZTE Blade Spark FirmwareZteusa ZTE Zmax PRO FirmwareZteusa ZTE Zmax Champ Firmware28/12/201817/6/2026
The ZTE Blade Vantage Android device with a build fingerprint of ZTE/Z839/sweet:7.1.1/NMF26V/20180120.095344:user/release-keys, the ZTE Blade Spark Android device with a build fingerprint of ZTE/Z971/peony:7.1.1/NMF26V/20171129.143111:user/release-keys, the ZTE ZMAX Pro Android device with a build fingerprint of…
ModificadaMedia (5.5)0.67%—HP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 FirmwareHP Proliant Xl750f Gen9 Server Firmware+973/12/201817/6/2026
The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system ROM updates which also addressed the…
ModificadaMedia (4.9)0.66%—Lenovo Flex System X240 M4 FirmwareLenovo Flex System X440 M4 FirmwareLenovo System X3750 M4 FirmwareIBM Bladecenter Hs23 Firmware+2516/11/201817/6/2026
A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash Descriptors.
ModificadaAlta (7.5)1.1%—Lenovo Flex System X240 M4 FirmwareLenovo Flex System X240 M5 FirmwareLenovo Flex System X280 X6 FirmwareLenovo Flex System X440 M4 Firmware+3826/7/201817/6/2026
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and…
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.
ModificadaCrítica (9.8)80%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
ModificadaCrítica (9.8)87%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
ModificadaCrítica (9.8)82%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
ModificadaAlta (7.5)1.8%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar.
ModificadaAlta (7.5)1.2%—Lenova Flex System X240 M5 FirmwareLenova Flex System X280 X6 FirmwareLenova Flex System X440 M4 FirmwareLenova Flex System X480 X6 Firmware+3826/1/201817/6/2026
An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a high volume of authentication failures via the Common Information Model (CIM) used by LXCA and OneCLI…
ModificadaCrítica (9.8)3.4%—Bladeenc21/9/201717/6/2026
A global buffer overflow was discovered in the iteration_loop function in loop.c in BladeEnc version 0.94.2. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.
ModificadaCrítica (9.8)2.7%—Ideablade Breeze.server.net22/6/201717/6/2026
IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.
Orbitaley — Vulnerabilidades