Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.21%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaMedia (4.4)0.17%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
ModificadaMedia (4.4)0.17%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
ModificadaAlta (7.8)0.29%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+4211/3/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
ModificadaAlta (7.8)0.29%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+4211/3/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
ModificadaAlta (7.8)0.29%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+4211/3/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
ModificadaAlta (7.8)0.29%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+4211/3/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
ModificadaAlta (7.8)0.29%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+4211/3/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
AnalizadaMedia (6.4)0.24%—Dell Precision 5820 Tower FirmwareDell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 Firmware+40724/1/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
AnalizadaMedia (6.4)0.25%—Dell Precision 7510 FirmwareDell Precision 7520 FirmwareDell Precision 7530 FirmwareDell Precision 7540 Firmware+40724/1/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaMedia (6.7)0.24%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+27912/11/202117/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaMedia (6.7)0.24%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+27912/11/202117/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaMedia (6.7)0.24%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+27912/11/202117/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaMedia (5.3)0.76%—Fimer Aurora Vision3/11/202117/6/2026
An issue was discovered in Fimer Aurora Vision before 2.97.10. The response to a failed login attempt discloses whether the username or password is wrong, helping an attacker to enumerate usernames. This can make a brute-force attack easier.
ModificadaMedia (4.3)0.78%—Fimer Aurora Vision3/11/202117/6/2026
An issue was discovered in Fimer Aurora Vision before 2.97.10. An attacker can (in the WebUI) obtain plant information without authentication by reading the response of APIs from a kiosk view of a plant.
ModificadaAlta (7.5)1.2%—Skyworthdigital Penguin Aurora BOX 41502 Firmware27/10/202117/6/2026
Skyworth Digital Technology Penguin Aurora Box 41502 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
ModificadaCrítica (10)0.96%—Skyworth Penguin Aurora BOX Firmware26/10/202117/6/2026
Penguin Aurora TV Box 41502 is a high-end network HD set-top box produced by Tencent Video and Skyworth Digital. An unauthorized access vulnerability exists in the Penguin Aurora Box. An attacker can use the vulnerability to gain unauthorized access to a specific link to remotely control the TV.
ModificadaAlta (7.5)17%💥 ExploitAfterlogic AuroraAfterlogic Webmail PRO7/3/202117/6/2026
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with…
ModificadaCrítica (9.8)7.1%—Afterlogic AuroraAfterlogic Webmail PRO4/3/202117/6/2026
An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x.
ModificadaMedia (6.1)0.80%—Afterlogic AuroraAfterlogic Webmail PRO26/11/201917/6/2026
Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name.
ModificadaMedia (6.1)0.93%—Afterlogic Aurora12/9/201917/6/2026
Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login.
ModificadaAlta (7.5)1.1%—Auroradao Aura9/5/201817/6/2026
The Owned smart contract implementation for Aurora DAO (AURA), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. An attacker can then conduct a lockBalances() denial of service attack.
ModificadaAlta (7.5)0.97%—Auroradao Idex Membership3/5/201817/6/2026
The Owned smart contract implementation for Aurora IDEX Membership (IDXM), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. A new owner can subsequently modify variables.
ModificadaMedia (4.8)0.52%—Afterlogic AuroraAfterlogic Webmail19/9/201717/6/2026
AdminPanel in AfterLogic WebMail 7.7 and Aurora 7.7.5 has XSS via the txtDomainName field to adminpanel/modules/pro/inc/ajax.php during addition of a domain.
AnalizadaCrítica (9.8)93%⚠ Explotación activa💥 ExploitApache AuroraApache ShiroRedhat FuseRedhat Jboss Middleware Text-only Advisories7/6/201617/6/2026
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Orbitaley — Vulnerabilidades