Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.23% | — | Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+129 | 12/11/2021 | 17/6/2026 | A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range. | |
| Modificada | Media (6.7) | 0.29% | — | Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+129 | 12/11/2021 | 17/6/2026 | A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.6) | 0.24% | — | Lenovo Thinkpad Helix FirmwareLenovo Thinkpad T550 FirmwareLenovo Thinkpad W550s FirmwareLenovo Thinkpad X1 Carbon 3RD GEN Firmware+17 | 16/7/2021 | 17/6/2026 | Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage. | |
| Modificada | Media (4.9) | 0.89% | — | Perforce Helix ALM | 13/4/2021 | 17/6/2026 | The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks. | |
| Modificada | Media (6.7) | 0.33% | — | Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+168 | 9/6/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. | |
| Modificada | Crítica (9.8) | 1.3% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access. | |
| Modificada | Media (6.4) | 0.33% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Media (6.4) | 0.35% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.40% | — | Lenovo Synaptics Thinkpad Ultranav DriverLenovo Thinkpad Helix FirmwareLenovo Thiankpad L430 FirmwareLenovo Thiankpad L530 Firmware+55 | 24/1/2019 | 17/6/2026 | In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user. | |
| Modificada | Alta (7.8) | 0.38% | — | Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+144 | 18/8/2017 | 17/6/2026 | A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path. | |
| Modificada | Media (4.4) | 0.30% | — | Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+70 | 30/11/2016 | 17/6/2026 | A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be… | |
| Modificada | Media (5) | 1.6% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted Open-PDU request that triggers incorrect DisplayString processing, a different vulnerability than… | |
| Modificada | Media (5) | 1.6% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (daemon crash) by establishing and closing a port-705 TCP connection, a different vulnerability than CVE-2012-1923. | |
| Modificada | Media (6.8) | 0.97% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to hijack the authentication of administrators for requests that cause a denial of service (stack consumption and daemon crash) via a malformed URL. | |
| Modificada | Media (4.3) | 1.8% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.1) | 38% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x store passwords in cleartext under adm_b_db\users\, which allows local users to obtain sensitive information by reading a database. | |
| Modificada | Alta (7.5) | 4.1% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 17/4/2012 | 16/6/2026 | Buffer overflow in rn5auth.dll in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to execute arbitrary code via crafted authentication credentials. | |
| Modificada | Alta (9.3) | 5.0% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 4/4/2011 | 16/6/2026 | Stack-based buffer overflow in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via a long string in an RTSP request. | |
| Modificada | Alta (10) | 4.1% | — | Realnetworks Helix ServerRealnetworks Helix Mobile Server | 4/4/2011 | 16/6/2026 | Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via vectors related to the x-wap-profile HTTP header. | |
| Modificada | Alta (10) | 5.1% | — | Realnetworks Helix Mobile ServerRealnetworks Helix ServerRealnetworks Helix Server Mobile | 20/4/2010 | 16/6/2026 | Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted payload length. | |
| Modificada | Alta (10) | 58% | 💥 Exploit | Realnetworks Helix Mobile ServerRealnetworks Helix ServerRealnetworks Helix Server Mobile | 20/4/2010 | 16/6/2026 | Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.6% | — | Realnetworks Helix DNA ServerRealnetworks Helix ServerRealnetworks Helix Server Mobile | 20/4/2010 | 16/6/2026 | Heap-based buffer overflow in the NTLM authentication functionality in RealNetworks Helix Server and Helix Mobile Server 11.x, 12.x, and 13.x allows remote attackers to have an unspecified impact via invalid base64-encoded data. | |
| Modificada | Media (5) | 4.2% | — | Realnetworks Helix PlayerRealnetworks Realplayer | 18/2/2010 | 16/6/2026 | Buffer overflow in common/util/rlstate.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a RuleBook structure with a large number of rule-separator characters that trigger heap memory corruption. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realplayer | 18/2/2010 | 16/6/2026 | Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is… | |
| Modificada | Alta (9.3) | 8.5% | — | Realnetworks RealplayerRealnetworks Realplayer EnterpriseRealnetworks Realplayer SPRealnetworks Helix Player | 25/1/2010 | 16/6/2026 | Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10 and 11.0.0, and Helix Player 10.x and 11.0.0 allows… |