Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

31 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.17%—Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+7610/2/202317/6/2026
Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service.
ModificadaMedia (5.5)0.14%—Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+7610/2/202317/6/2026
Dell PowerEdge BIOS and Dell Precision BIOS contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause a denial of service during SMM.
ModificadaMedia (6)0.21%—Dell R6415 FirmwareDell R7415 FirmwareDell R7425 FirmwareDell R730 Firmware+1621/4/202217/6/2026
Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A Local High Privileged attacker could potentially exploit this vulnerability leading to arbitrary writes or denial of service.
ModificadaAlta (8.8)3.2%—GE Rt430 FirmwareGE Rt431 FirmwareGE Rt434 Firmware18/3/202217/6/2026
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
ModificadaMedia (5.3)0.86%—GE Rt430 FirmwareGE Rt431 FirmwareGE Rt434 Firmware18/3/202217/6/2026
By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, attackers would be able to intercept and decrypt encrypted traffic through an HTTPS connection.
ModificadaCrítica (9.8)2.3%—GE Rt430 FirmwareGE Rt431 FirmwareGE Rt434 Firmware2/6/202017/6/2026
GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application could allow multiple unauthenticated attacks that could cause serious impact. The vulnerability may allow an unauthenticated attacker to execute arbitrary commands and…
Orbitaley — Vulnerabilidades