Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.20% | — | Intel Chipset Software Installation UtilityAI | 12/2/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) Chipset Software Installation Utility before version 10.1.19867.8574 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.5) | 0.60% | — | Matter Project ChipAIConnectedhomeipAI | 18/12/2024 | 17/6/2026 | In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with zero messageSize, leading to denial of service. | |
| Aplazada | Alta (8.8) | 0.56% | — | Cypress Cyw43455AIBroadcom Wireless Combo ChipsAI | 11/11/2024 | 17/6/2026 | Certain Cypress (and Broadcom) Wireless Combo chips such as CYW43455, when a 2021-01-26 Bluetooth firmware update is not present, allow a Bluetooth outage via a "Spectra" attack. | |
| Aplazada | Media (5.5) | 0.39% | — | Cypress Wireless Combo ChipsAIBroadcom Wireless Combo ChipsAI | 10/11/2024 | 17/6/2026 | Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow inferences about memory content via a "Spectra" attack. | |
| Aplazada | Media (5.5) | 0.39% | — | Cypress Wireless Combo ChipsAIBroadcom Wireless Combo ChipsAI | 10/11/2024 | 17/6/2026 | Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory access via a "Spectra" attack. | |
| Aplazada | Media (4.3) | 0.23% | — | Microchip Rn4870AI | 16/10/2024 | 17/6/2026 | On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked. | |
| Aplazada | Crítica (9.1) | 0.45% | — | C-chip CchipamaotaAI | 11/10/2024 | 5/7/2026 | An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process. | |
| Analizada | Alta (8.5) | 16% | — | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | |
| Analizada | Media (6.3) | 0.84% | — | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | |
| Analizada | Alta (7.7) | 0.83% | — | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | |
| Analizada | Media (5.4) | 13% | — | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | |
| Analizada | Alta (8.7) | 0.44% | — | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | |
| Modificada | Alta (8.7) | 0.21% | — | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0. | |
| Modificada | Alta (8.7) | 0.23% | — | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0. | |
| Analizada | Crítica (9.5) | 1.4% | — | Microchip Advanced Software Framework | 8/8/2024 | 17/6/2026 | Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software… | |
| Analizada | Alta (7.3) | 0.18% | — | Intel Chipset Device Software | 16/5/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.7) | 0.17% | — | Intel Onboard Video DriverAIIntel 62X ChipsetAI | 16/5/2024 | 17/6/2026 | Incorrect default permissions in some onboard video driver software before version 1.14 for Intel(R) Server Boards based on Intel(R) 62X Chipset may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.3) | 0.21% | — | Microchip SAM E70AIMicrochip SAM S70AIMicrochip SAM V70AIMicrochip SAM V71AI+8 | 16/5/2024 | 17/6/2026 | A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71, SAM G55, SAM 4C/4S/4N/4E, and SAM 3S/3N/3U microcontrollers allows access to the memory bus via the debug interface even if the security bit is set. | |
| Aplazada | Alta (8.7) | 0.55% | — | Microchip Mpfs2AI | 18/4/2024 | 17/6/2026 | The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentication. The MPFS2 file system module provides a light-weight read-only file system that can be stored in external EEPROM, external serial flash, or internal flash program memory. This file system serves… | |
| Analizada | Alta (7.8) | 0.17% | — | Intel Chipset Device Software | 14/2/2024 | 17/6/2026 | Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.17% | — | Intel Chipset Device Software | 14/2/2024 | 17/6/2026 | Improper access control in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.25% | — | EMC Elan Match-on-chip FPR Solution Firmware | 12/1/2024 | 17/6/2026 | ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity. Version which is lower than 3.0.12011.08009(Legacy)/3.3.12011.08103(ESS)… | |
| Modificada | Crítica (9.8) | 0.65% | — | Microchip Maxview Storage Manager | 9/1/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default… | |
| Modificada | Crítica (10) | 0.53% | — | Microchip Maxview Storage Manager | 8/1/2024 | 17/6/2026 | In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can occur, with data modification and information disclosure. This affects 3.00.23484 through 4.14.00.26064 (except for the patched… | |
| Modificada | Media (5.4) | 0.38% | — | Assortedchips Drawit | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in assorted[chips] DrawIt (draw.Io) plugin <= 1.1.3 versions. |