Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.13% | — | Intel UefiAI | 11/11/2025 | 17/6/2026 | Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable data alteration. This result may potentially occur via local access when attack… | |
| Aplazada | Media (6.7) | 0.18% | — | Nvidia BluefieldAINvidia ConnectxAI | 22/10/2025 | 17/6/2026 | NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor with high privilege access to execute arbitrary code. | |
| Aplazada | Alta (7.6) | 0.32% | — | Nvidia Jetson LinuxAINvidia UefiAI | 14/10/2025 | 17/6/2026 | NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause corruption of the Linux Device Tree. A successful exploitation of this vulnerability might lead to data tampering, denial of service. | |
| Aplazada | Alta (7.6) | 0.26% | — | Intel Uefi FirmwareAI | 14/10/2025 | 17/6/2026 | Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the… | |
| Aplazada | Alta (8.7) | 0.15% | — | Nvidia BluefieldAI | 4/9/2025 | 17/6/2026 | NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Media (5.6) | 0.13% | — | Intel Uefi Oobras Mmbhandler DriverAI | 12/8/2025 | 17/6/2026 | Missing release of memory after effective lifetime in the UEFI OobRasMmbiHandlerDriver module for some Intel(R) reference server platforms may allow a privileged user to enable denial of service via local access. | |
| Aplazada | Alta (8.2) | 0.43% | — | Microsoft Uefi FirmwareAI | 10/6/2025 | 17/6/2026 | An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security… | |
| Aplazada | Alta (8.7) | 0.16% | — | Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI | 13/5/2025 | 17/6/2026 | Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.6) | 0.15% | — | Intel Uefi Firmware D50dnpAIIntel Uefi Firmware M50fcpAI | 13/5/2025 | 17/6/2026 | Improper initialization in the UEFI firmware for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (8.7) | 0.16% | — | Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI | 13/5/2025 | 17/6/2026 | Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.11% | — | Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI | 13/5/2025 | 17/6/2026 | Time-of-check time-of-use race condition in the UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to enable escalation of privilege via local access. | |
| Aplazada | Media (5.6) | 0.16% | — | Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI | 13/5/2025 | 17/6/2026 | Improper input validation in the UEFI firmware GenerationSetup module for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via local access. | |
| Analizada | Alta (7.5) | 0.43% | — | Canonical Linux-bluefield | 31/3/2025 | 17/6/2026 | Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield package. | |
| Aplazada | Media (6.8) | 0.22% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (6.8) | 0.23% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (8.7) | 0.19% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.25% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.25% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.8) | 0.25% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (8.7) | 0.25% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.8) | 0.20% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (8.7) | 0.28% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.25% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.3) | 0.33% | — | I3verticals Truefiling | 17/1/2025 | 17/6/2026 | TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect public legal documentation into cases. TrueFiling is an entirely cloud-hosted application. Prior to version 3.1.112.19, TrueFiling trusted some client-controlled… | |
| Aplazada | Media (5.4) | 0.15% | — | Intel Server M20ntp Family UefiAI | 13/11/2024 | 17/6/2026 | Improper input validation in firmware for some Intel(R) Server M20NTP Family UEFI may allow a privileged user to potentially enable escalation of privilege via local access. |