Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.4) | 0.25% | — | Dell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 FirmwareDell Precision 7540 Firmware+407 | 24/1/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Media (6.7) | 0.24% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+279 | 12/11/2021 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Media (6.7) | 0.24% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+279 | 12/11/2021 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Media (6.7) | 0.24% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+279 | 12/11/2021 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Media (6.7) | 0.25% | — | Dell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G3 15 3500 FirmwareDell G3 15 3590 Firmware+81 | 28/9/2021 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.5) | 0.29% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions. | |
| Modificada | Alta (7.5) | 0.28% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions. | |
| Modificada | Alta (7.5) | 0.26% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions. | |
| Modificada | Media (6.5) | 0.54% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering. |