Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.26% | — | Lenovo C340-14iml FirmwareLenovo C340-15iml FirmwareLenovo D330-10igm FirmwareLenovo Duet 3-10igl5 Firmware+58 | 22/4/2022 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Crítica (9.1) | 1.5% | — | Vmware Carbon Black APP Control | 23/3/2022 | 17/6/2026 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where… | |
| Modificada | Crítica (9.1) | 20% | — | Vmware Carbon Black APP Control | 23/3/2022 | 17/6/2026 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute… | |
| Modificada | Media (5.5) | 0.23% | — | Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+129 | 12/11/2021 | 17/6/2026 | A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range. | |
| Modificada | Media (6.7) | 0.29% | — | Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+129 | 12/11/2021 | 17/6/2026 | A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.6) | 0.24% | — | Lenovo Thinkpad Helix FirmwareLenovo Thinkpad T550 FirmwareLenovo Thinkpad W550s FirmwareLenovo Thinkpad X1 Carbon 3RD GEN Firmware+17 | 16/7/2021 | 17/6/2026 | Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage. | |
| Modificada | Crítica (9.8) | 11% | — | Vmware Carbon Black APP Control | 23/6/2021 | 17/6/2026 | VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate. | |
| Modificada | Crítica (9.1) | 1.4% | — | Vmware Carbon Black Cloud Workload | 1/4/2021 | 17/6/2026 | VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue… | |
| Modificada | Media (5.4) | 0.54% | — | Carbonite Server Backup Portal | 12/1/2021 | 17/6/2026 | OpenText Carbonite Server Backup Portal before 8.8.7 allows XSS by an authenticated user via policy creation. | |
| Modificada | Baja (3.6) | 0.21% | — | Vmware Carbon Black Cloud | 16/12/2020 | 17/6/2026 | The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited number of files with output from the sensor installation. | |
| Modificada | Baja (2.4) | 0.35% | — | Lenovo Thinkpad T490 (20nx) FirmwareLenovo Thinkpad T490 (20qx) FirmwareLenovo Thinkpad T490 (20rx) FirmwareLenovo Thinkpad T490s (20nx) Firmware+6 | 1/9/2020 | 17/6/2026 | In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx… | |
| Modificada | Media (6.8) | 0.31% | — | Lenovo Thinkpad A275 FirmwareLenovo Thinkpad A285 FirmwareLenovo Thinkpad A475 FirmwareLenovo Thinkpad A485 Firmware+4 | 1/9/2020 | 17/6/2026 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access. | |
| Modificada | Alta (7.8) | 0.51% | — | Synaptics Vfs75xx FirmwareLenovo Thinkpad 25 FirmwareLenovo Thankpad A475 FirmwareLenovo Thankpad A485 Firmware+108 | 22/7/2020 | 17/6/2026 | Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers. | |
| Modificada | Media (6) | 0.55% | — | Synaptics Vfs75xx FirmwareLenovo Thinkpad 25 FirmwareLenovo Thankpad A475 FirmwareLenovo Thankpad A485 Firmware+129 | 22/7/2020 | 17/6/2026 | Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table. | |
| Modificada | Media (6.8) | 0.30% | — | Lenovo Thinkpad E14 FirmwareLenovo Thinkpad E15 FirmwareLenovo Thinkpad R14 FirmwareLenovo Thinkpad S3 GEN 2 Firmware+34 | 9/6/2020 | 17/6/2026 | Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash. | |
| Modificada | Media (6.7) | 0.33% | — | Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+168 | 9/6/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. | |
| Modificada | Media (6.8) | 0.28% | — | Lenovo Thinkpad 11E Yoga GEN 6 FirmwareLenovo Thinkpad 11E FirmwareLenovo Thinkpad Yoga 11E 3RD GEN FirmwareLenovo Thinkpad Yoga 11E 4TH GEN Firmware+96 | 9/6/2020 | 17/6/2026 | An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. | |
| Modificada | Media (5.5) | 0.97% | 💥 Exploit | Taskautomation Carbonftp | 21/1/2020 | 17/6/2026 | CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary. | |
| Modificada | Crítica (9.8) | 1.3% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access. | |
| Modificada | Media (6.4) | 0.33% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Media (6.4) | 0.35% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Media (6.5) | 1.2% | — | Lenovo Legion Y520t Z370 FirmwareLenovo Aio310-20iap FirmwareLenovo Aio510-22ish FirmwareLenovo Aio510-23ish Firmware+104 | 29/8/2019 | 17/6/2026 | There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at a higher privilege. The following are affected products and versions: Legion Y520T_Z370 6.0.1.8642, AIO310-20IAP 6.0.1.8642, AIO510-22ISH 6.0.1.8642, AIO510-23ISH… | |
| Modificada | Crítica (9.8) | 3.6% | — | Fujifilm Cr-ir 357 FCR Carbon X FirmwareFujifilm Cr-ir 357 FCR Xc-2 FirmwareFujifilm Cr-ir 357 FCR Capsula X Firmware | 30/4/2019 | 17/6/2026 | Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who successfully exploits this vulnerability may be able to access the underlying operating system. | |
| Modificada | Alta (7.5) | 1.6% | — | Fujifilm Cr-ir 357 FCR Carbon X FirmwareFujifilm Cr-ir 357 FCR Xc-2 FirmwareFujifilm Cr-ir 357 FCR Capsula X Firmware | 30/4/2019 | 17/6/2026 | Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X are susceptible to a denial-of-service condition as a result of an overflow of TCP packets, which requires the device to be manually rebooted. | |
| Modificada | Alta (7.8) | 0.40% | — | Lenovo Synaptics Thinkpad Ultranav DriverLenovo Thinkpad Helix FirmwareLenovo Thiankpad L430 FirmwareLenovo Thiankpad L530 Firmware+55 | 24/1/2019 | 17/6/2026 | In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user. |