Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.17% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (6.7) | 0.17% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (6.7) | 0.21% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (6.7) | 0.17% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (6.7) | 0.17% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (6.7) | 0.17% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (6.7) | 0.21% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (6.7) | 0.17% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (6.7) | 0.17% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 16/3/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (6.7) | 0.17% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 10/2/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | |
| Modificada | Media (5.5) | 0.14% | — | Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+76 | 10/2/2023 | 17/6/2026 | Dell PowerEdge BIOS and Dell Precision BIOS contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause a denial of service during SMM. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+321 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (4.3) | 0.41% | — | Lenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile Hx1021 FirmwareLenovo Thinkagile Hx1320 Firmware+94 | 30/1/2023 | 17/6/2026 | The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect. | |
| Modificada | Media (6.5) | 0.63% | — | Lenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile Hx1021 FirmwareLenovo Thinkagile Hx1320 Firmware+94 | 30/1/2023 | 17/6/2026 | A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service. | |
| Modificada | Media (6.7) | 0.27% | — | Lenovo Thinkpad 11E FirmwareLenovo Thinkpad Helix FirmwareLenovo Thinkpad L560 FirmwareLenovo Thinkpad L570 Firmware+26 | 22/4/2022 | 17/6/2026 | During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code. | |
| Modificada | Media (5.5) | 0.23% | — | Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+129 | 12/11/2021 | 17/6/2026 | A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range. | |
| Modificada | Media (6.7) | 0.29% | — | Lenovo Thinkpad X380 Yoga FirmwareLenovo Thinkpad X1 Fold GEN 1 FirmwareLenovo Thinkpad Yoga 260 FirmwareLenovo Thinkpad Yoga 11E 3RD GEN Firmware+129 | 12/11/2021 | 17/6/2026 | A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.6) | 0.24% | — | Lenovo Thinkpad Helix FirmwareLenovo Thinkpad T550 FirmwareLenovo Thinkpad W550s FirmwareLenovo Thinkpad X1 Carbon 3RD GEN Firmware+17 | 16/7/2021 | 17/6/2026 | Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage. | |
| Modificada | Media (6.7) | 0.33% | — | Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+168 | 9/6/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. | |
| Modificada | Crítica (9.8) | 3.7% | — | Timetoolsltd Sr9850 FirmwareTimetoolsltd Sr9750 FirmwareTimetoolsltd Sc9705 FirmwareTimetoolsltd Sr9210 Firmware+6 | 13/2/2020 | 17/6/2026 | TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie." | |
| Modificada | Crítica (9.8) | 2.7% | — | Timetoolsltd Sr9850 FirmwareTimetoolsltd Sr9750 FirmwareTimetoolsltd Sc9705 FirmwareTimetoolsltd Sr9210 Firmware+6 | 13/2/2020 | 17/6/2026 | TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel or srtime parameter. | |
| Modificada | Crítica (9.8) | 1.3% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access. | |
| Modificada | Media (6.4) | 0.33% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Media (6.4) | 0.35% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.40% | — | Lenovo Synaptics Thinkpad Ultranav DriverLenovo Thinkpad Helix FirmwareLenovo Thiankpad L430 FirmwareLenovo Thiankpad L530 Firmware+55 | 24/1/2019 | 17/6/2026 | In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user. |