Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

96 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)0.13%—Intel UefiAI11/11/202517/6/2026
Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable data alteration. This result may potentially occur via local access when attack…
AplazadaMedia (6.7)0.18%—Nvidia BluefieldAINvidia ConnectxAI22/10/202517/6/2026
NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor with high privilege access to execute arbitrary code.
AplazadaAlta (7.6)0.32%—Nvidia Jetson LinuxAINvidia UefiAI14/10/202517/6/2026
NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause corruption of the Linux Device Tree. A successful exploitation of this vulnerability might lead to data tampering, denial of service.
AplazadaAlta (7.6)0.26%—Intel Uefi FirmwareAI14/10/202517/6/2026
Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the…
AplazadaAlta (8.7)0.15%—Nvidia BluefieldAI4/9/202517/6/2026
NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
AplazadaMedia (5.6)0.13%—Intel Uefi Oobras Mmbhandler DriverAI12/8/202517/6/2026
Missing release of memory after effective lifetime in the UEFI OobRasMmbiHandlerDriver module for some Intel(R) reference server platforms may allow a privileged user to enable denial of service via local access.
AplazadaAlta (8.2)0.43%—Microsoft Uefi FirmwareAI10/6/202517/6/2026
An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security…
AplazadaAlta (8.7)0.16%—Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI13/5/202517/6/2026
Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.6)0.15%—Intel Uefi Firmware D50dnpAIIntel Uefi Firmware M50fcpAI13/5/202517/6/2026
Improper initialization in the UEFI firmware for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via local access.
AplazadaAlta (8.7)0.16%—Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI13/5/202517/6/2026
Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.7)0.11%—Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI13/5/202517/6/2026
Time-of-check time-of-use race condition in the UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to enable escalation of privilege via local access.
AplazadaMedia (5.6)0.16%—Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI13/5/202517/6/2026
Improper input validation in the UEFI firmware GenerationSetup module for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via local access.
AnalizadaAlta (7.5)0.43%—Canonical Linux-bluefield31/3/202517/6/2026
Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield package.
AplazadaMedia (6.8)0.22%—Intel Uefi FirmwareAI12/2/202517/6/2026
Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access.
AplazadaMedia (6.8)0.23%—Intel Uefi FirmwareAI12/2/202517/6/2026
Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
AplazadaAlta (8.7)0.19%—Intel Uefi FirmwareAI12/2/202517/6/2026
Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.7)0.25%—Intel Uefi FirmwareAI12/2/202517/6/2026
Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.7)0.25%—Intel Uefi FirmwareAI12/2/202517/6/2026
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.8)0.25%—Intel Uefi FirmwareAI12/2/202517/6/2026
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
AplazadaAlta (8.7)0.25%—Intel Uefi FirmwareAI12/2/202517/6/2026
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.8)0.20%—Intel Uefi FirmwareAI12/2/202517/6/2026
Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
AplazadaAlta (8.7)0.28%—Intel Uefi FirmwareAI12/2/202517/6/2026
Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.7)0.25%—Intel Uefi FirmwareAI12/2/202517/6/2026
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
AnalizadaMedia (6.3)0.33%—I3verticals Truefiling17/1/202517/6/2026
TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect public legal documentation into cases. TrueFiling is an entirely cloud-hosted application. Prior to version 3.1.112.19, TrueFiling trusted some client-controlled…
AplazadaMedia (5.4)0.15%—Intel Server M20ntp Family UefiAI13/11/202417/6/2026
Improper input validation in firmware for some Intel(R) Server M20NTP Family UEFI may allow a privileged user to potentially enable escalation of privilege via local access.