Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2491 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.51% | — | Vmware WorkstationVmware Fusion | 14/5/2024 | 17/6/2026 | VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine. | |
| Modificada | Media (6.5) | 0.50% | — | Vmware WorkstationVmware Fusion | 14/5/2024 | 17/6/2026 | VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition. | |
| Modificada | Alta (8.2) | 0.68% | — | Vmware FusionVmware Workstation | 14/5/2024 | 17/6/2026 | VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. | |
| Analizada | Alta (7.1) | 2.3% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | |
| Analizada | Media (6.7) | 0.65% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained… | |
| Modificada | Media (6.7) | 3.5% | — | Vmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained… | |
| Analizada | Media (4.4) | 0.23% | — | Vmware FusionVmware Workstation | 29/2/2024 | 17/6/2026 | VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure. | |
| Analizada | Alta (7.9) | 0.19% | — | HP Z440 Workstation FirmwareHP Z640 Workstation FirmwareHP Z840 Workstation Firmware | 14/2/2024 | 17/6/2026 | A potential security vulnerability has been identified in the system BIOS for certain HP Workstation PCs, which might allow escalation of privilege, arbitrary code execution, or denial of service. HP is releasing mitigation for the potential vulnerability. | |
| Analizada | Alta (7.8) | 28% | ⚠ Explotación activa | Netapp H300s FirmwareNetapp H500s FirmwareNetapp H700s FirmwareNetapp H410s Firmware+14 | 31/1/2024 | 7/8/2026 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when… | |
| Modificada | Crítica (9.8) | 1.9% | — | IBM Merge Efilm Workstation | 26/1/2024 | 17/6/2026 | A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution with SYSTEM privileges. | |
| Modificada | Crítica (9.8) | 1.9% | — | IBM Merge Efilm Workstation | 26/1/2024 | 17/6/2026 | A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution. | |
| Modificada | Alta (7.8) | 0.16% | — | IBM Merge Efilm Workstation | 26/1/2024 | 17/6/2026 | An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated attacker can exploit this vulnerability to escalate privileges to SYSTEM. | |
| Modificada | Crítica (9.8) | 1.7% | — | IBM Merge Efilm Workstation | 26/1/2024 | 17/6/2026 | A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disclosure or remote code execution. | |
| Modificada | Alta (7.8) | 0.36% | — | TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+8 | 18/1/2024 | 17/6/2026 | A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context. | |
| Modificada | Media (5.5) | 0.32% | — | TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+8 | 18/1/2024 | 17/6/2026 | A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX… | |
| Modificada | Crítica (9.8) | 2.1% | — | X.org X ServerX.org XwaylandFedoraproject FedoraRedhat Enterprise Linux Desktop+3 | 18/1/2024 | 17/6/2026 | A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow… | |
| Modificada | Media (6.5) | 0.57% | — | FreeipaFedoraproject FedoraRedhat Codeready Linux BuilderRedhat Enterprise Linux+17 | 10/1/2024 | 17/6/2026 | A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration… | |
| Modificada | Alta (8.8) | 4.3% | — | PostgresqlRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUS+17 | 10/12/2023 | 17/6/2026 | A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data.… | |
| Modificada | Media (6.7) | 0.22% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre G5-14imb05 Firmware+57 | 8/11/2023 | 17/6/2026 | A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables. | |
| Modificada | Media (6.7) | 0.22% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre G5-14imb05 Firmware+57 | 8/11/2023 | 17/6/2026 | A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables. | |
| Modificada | Media (6.7) | 0.22% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre G5-14imb05 Firmware+57 | 8/11/2023 | 17/6/2026 | A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables. | |
| Modificada | Media (6.7) | 0.22% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre G5-14imb05 Firmware+57 | 8/11/2023 | 17/6/2026 | A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables. | |
| Modificada | Media (6.7) | 0.22% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre G5-14imb05 Firmware+57 | 8/11/2023 | 17/6/2026 | A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. |