Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.17%—Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+7616/3/202317/6/2026
Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service.
ModificadaMedia (6.7)0.17%—Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+7616/3/202317/6/2026
Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service.
ModificadaMedia (6.7)0.17%—Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+7610/2/202317/6/2026
Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service.
ModificadaMedia (5.5)0.14%—Dell R6515 FirmwareDell R7515 FirmwareDell R6525 FirmwareDell R7525 Firmware+7610/2/202317/6/2026
Dell PowerEdge BIOS and Dell Precision BIOS contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause a denial of service during SMM.
ModificadaMedia (6.5)0.60%—Siemens Desigo Dxr2 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc5 Firmware20/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The application, after a successful login, sets the session cookie on the browser via…
ModificadaAlta (7.5)0.90%—Siemens Desigo Dxr2 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc5 Firmware20/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application does not employ any countermeasures against…
ModificadaMedia (5.3)1.1%—Siemens Desigo Dxr2 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc5 Firmware20/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application fails to normalize the response times of…
ModificadaCrítica (9.1)0.98%—Siemens Desigo Pxc5 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Dxr2 Firmware10/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application returns an AuthToken that does not expire at the defined auto logoff…
ModificadaMedia (6.5)0.48%—Siemens Desigo Pxc5 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Dxr2 Firmware10/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application stores the PBKDF2 derived key of users passwords with a low…
ModificadaMedia (6.5)0.85%—Siemens Desigo Pxc5 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Dxr2 Firmware10/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application fails to enforce an upper bound to the cost factor of the PBKDF2…
ModificadaAlta (7.5)0.93%—Siemens Desigo Dxr2 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc5 Firmware10/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). When the controller receives a specific BACnet protocol packet, an exception causes the…
ModificadaMedia (6.7)0.35%—Dell Poweredge R640 FirmwareDell Poweredge R740 FirmwareDell Poweredge R740xd FirmwareDell Poweredge R940 Firmware+2714/6/202117/6/2026
Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of service, arbitrary code execution, or information disclosure in System Management Mode.
Orbitaley — Vulnerabilidades