Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

202 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.50%—AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+199/5/202317/6/2026
Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity.
ModificadaMedia (6.8)0.32%—AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+449/5/202317/6/2026
Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution.
ModificadaAlta (8.8)0.78%—AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+449/5/202317/6/2026
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution.
ModificadaAlta (7.5)0.63%—AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+449/5/202317/6/2026
Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service.
ModificadaAlta (7.5)0.49%—AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+449/5/202317/6/2026
Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity.
ModificadaCrítica (9.1)0.35%—AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+449/5/202317/6/2026
Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.
ModificadaAlta (7.1)0.18%—AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+199/5/202317/6/2026
Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability.
ModificadaCrítica (9.8)0.68%—AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+449/5/202317/6/2026
Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.
ModificadaMedia (5.5)0.19%—AMD Epyc 7773x FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 Firmware+1249/5/202317/6/2026
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.
ModificadaAlta (7.4)0.40%—AMD Epyc 7001 FirmwareAMD Epyc 7251 FirmwareAMD Epyc 7261 FirmwareAMD Epyc 7281 Firmware+949/5/202317/6/2026
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.
ModificadaMedia (5.5)0.18%—AMD Epyc 7773x FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 Firmware+1489/5/202317/6/2026
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.
AnalizadaMedia (6.1)0.36%—Draytek Vigor2860 FirmwareDraytek Vigor2860n FirmwareDraytek Vigor2860n-plus FirmwareDraytek Vigor2860vn-plus Firmware+873/3/202317/6/2026
Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web application management portal. This affects Vigor3910, Vigor1000B, Vigor2962 v4.3.2.1; Vigor2865 and Vigor2866 v4.4.1.0; Vigor2927 v4.4.2.2; and Vigor2915, Vigor2765, Vigor2766,…
ModificadaMedia (6.7)0.31%—Mediatek Mt5221 FirmwareMediatek Mt7603 FirmwareMediatek Mt7613 FirmwareMediatek Mt7615 Firmware+266/2/202317/6/2026
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220705035; Issue ID: GN20220705035.
ModificadaMedia (6.7)0.31%—Mediatek Mt5221 FirmwareMediatek Mt7603 FirmwareMediatek Mt7613 FirmwareMediatek Mt7615 Firmware+266/2/202317/6/2026
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220705028; Issue ID: GN20220705028.
ModificadaMedia (6.7)0.31%—Mediatek Mt5221 FirmwareMediatek Mt7603 FirmwareMediatek Mt7613 FirmwareMediatek Mt7615 Firmware+266/2/202317/6/2026
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220705011; Issue ID: GN20220705011.
ModificadaCrítica (9.8)14%—Lexmark B2236 FirmwareLexmark B2338 FirmwareLexmark B2442 FirmwareLexmark B2546 Firmware+12423/1/202317/6/2026
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
ModificadaAlta (7.5)28%💥 PoCLexmark B2236 FirmwareLexmark B2338 FirmwareLexmark B2442 FirmwareLexmark B2546 Firmware+12423/1/202317/6/2026
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
ModificadaMedia (5.3)0.56%—AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+4611/1/202317/6/2026
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
ModificadaAlta (7.5)0.62%—AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+4611/1/202317/6/2026
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.
ModificadaAlta (7.5)0.62%—AMD Epyc 7003 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p Firmware+2011/1/202317/6/2026
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
ModificadaAlta (7.5)0.62%—AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+4611/1/202317/6/2026
Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.
ModificadaBaja (2.4)0.24%—AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+4611/1/202317/6/2026
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
ModificadaMedia (6.5)0.60%—AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+6011/1/202317/6/2026
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.
ModificadaMedia (6.5)0.60%—AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+4611/1/202317/6/2026
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.
ModificadaMedia (5.7)0.18%—AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+4611/1/202317/6/2026
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.