Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.24% | — | Intel Lapbc510 FirmwareIntel Lapbc710 FirmwareIntel Lapkc71f FirmwareIntel Lapkc71e Firmware+55 | 12/5/2022 | 17/6/2026 | Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel Lapbc510 FirmwareIntel Lapbc710 FirmwareIntel Lapkc71f FirmwareIntel Lapkc71e Firmware+55 | 12/5/2022 | 17/6/2026 | Improper buffer access in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.6) | 0.25% | — | Intel Active Management Technology Software Development KITIntel Setup AND Configuration SoftwareIntel Management Engine Bios ExtensionIntel Core I3 Firmware+176 | 9/2/2022 | 17/6/2026 | Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical… | |
| Modificada | Media (5.5) | 0.22% | — | Intel NUC M15 Laptop KIT Lapbc510 FirmwareIntel NUC M15 Laptop KIT Lapbc710 FirmwareIntel NUC 11 Compute Element Cm11ebc4w FirmwareIntel NUC 11 Compute Element Cm11ebi38w Firmware+99 | 17/11/2021 | 17/6/2026 | Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (6.7) | 0.28% | — | Lenovo Thinkpad 11E 3RD GEN FirmwareLenovo Thinkpad 11E 4TH GEN I3 FirmwareLenovo Thinkpad 11E 4TH GEN I7 FirmwareLenovo Thinkpad 11E 4TH GEN I5 Firmware+25 | 12/11/2021 | 17/6/2026 | A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.6) | 0.22% | — | Lenovo Thinkpad 11E 3RD GEN FirmwareLenovo Thinkpad 11E 4TH GEN I3 FirmwareLenovo Thinkpad 11E 4TH GEN I7 FirmwareLenovo Thinkpad 11E 4TH GEN I5 Firmware+35 | 12/11/2021 | 17/6/2026 | A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS. | |
| Modificada | Media (6.7) | 0.24% | — | Intel NUC M15 Laptop KIT Lapbc510 FirmwareIntel NUC M15 Laptop KIT Lapbc710 FirmwareIntel NUC 11 Compute Element Cm11ebc4 FirmwareIntel NUC 11 Compute Element Cm11ebi38w Firmware+73 | 9/6/2021 | 17/6/2026 | Improper access control in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel NUC M15 Laptop KIT Lapbc510 FirmwareIntel NUC M15 Laptop KIT Lapbc710 FirmwareIntel NUC 11 Compute Element Cm11ebc4 FirmwareIntel NUC 11 Compute Element Cm11ebi38w Firmware+73 | 9/6/2021 | 17/6/2026 | Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.6) | 0.31% | — | Resourcexpress Qubi3 Firmware | 17/11/2020 | 17/6/2026 | QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obtain sensitive information via the debug interface (keystrokes over a USB cable), aka wireless password visibility. | |
| Modificada | Media (4.8) | 0.95% | — | Jisiwei I3 Firmware | 19/7/2019 | 17/6/2026 | A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner, while adding a device to the account using a QR-code. The QR-code follows an easily predictable pattern that depends only on the specific device ID of the robot vacuum cleaner. By generating a QR-code containing information about… | |
| Modificada | Media (5.6) | 0.48% | — | Jisiwei I3 Firmware | 19/7/2019 | 17/6/2026 | A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner. Actions performed on the app such as changing a password, and personal information it communicates with the server, use unencrypted HTTP. As an example, while logging in through the app to a Jisiwei account, the login request is… | |
| Modificada | Alta (8.8) | 2.4% | — | Hikvision Ds-2cd2032-i FirmwareHikvision Ds-2cd2112-i FirmwareHikvision Ds-2cd2132-i FirmwareHikvision Ds-2cd2212-i5 Firmware+54 | 6/5/2017 | 17/6/2026 | A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Hikvision Ds-2cd2032-i FirmwareHikvision Ds-2cd2112-i FirmwareHikvision Ds-2cd2132-i FirmwareHikvision Ds-2cd2212-i5 Firmware+54 | 6/5/2017 | 17/6/2026 | An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build… |