Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
230 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.71% | — | Libbiosig Project Libbiosig | 25/8/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability… | |
| Modificada | Crítica (9.8) | 0.74% | — | Libbiosig Project Libbiosig | 25/8/2025 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted .nex file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.93% | — | Libbiosig Project Libbiosig | 25/8/2025 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the ISHNE parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted ISHNE ECG annotations file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.74% | — | Libbiosig Project Libbiosig | 25/8/2025 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.86% | — | Libbiosig Project Libbiosig | 25/8/2025 | 17/6/2026 | An integer overflow vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted ABF file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.93% | — | Libbiosig Project Libbiosig | 25/8/2025 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.68% | — | Libbiosig Project Libbiosig | 25/8/2025 | 17/6/2026 | An integer overflow vulnerability exists in the GDF parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted GDF file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 0.51% | — | Libbiosig Project Libbiosig | 25/8/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted .nex file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.74% | — | Libbiosig Project Libbiosig | 25/8/2025 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the RHS2000 parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted RHS2000 file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.88% | — | Libbiosig Project Libbiosig | 25/8/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Aplazada | Alta (7.3) | 0.17% | — | HP System BiosAI | 13/8/2025 | 17/6/2026 | A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escalation of privilege, arbitrary code execution, denial of service, or information disclosure via a physical attack that requires specialized equipment and knowledge. HP is releasing firmware mitigation… | |
| Aplazada | Media (6.3) | 0.21% | — | Edk2 BiosAITianocore Edk2AI | 12/8/2025 | 17/6/2026 | EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service. | |
| Aplazada | Media (4.4) | 0.17% | — | SEL BiosAI | 12/5/2025 | 17/6/2026 | SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and change password-protected BIOS settings by importing a BIOS settings file with no password set. | |
| Aplazada | Baja (3.5) | 0.24% | — | Edk2 BiosAITianocore Edk2AI | 14/3/2025 | 17/6/2026 | EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service. | |
| Aplazada | Media (5.4) | 0.19% | — | Intel Server M50fcp Bios AND System Firmware Update PackageAI | 12/2/2025 | 17/6/2026 | Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family before version R01.02.0002 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.14% | — | Intel Server M20ntp BiosAI | 13/11/2024 | 17/6/2026 | Use after free in the UEFI firmware of some Intel(R) Server M20NTP BIOS may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.1) | 0.19% | — | Intel Server Board S2600st Family BiosAIIntel Firmware Update SoftwareAI | 13/11/2024 | 17/6/2026 | Improper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.18% | — | Intel Server Board S2600st Family Bios AND Firmware UpdateAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path for the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Crítica (9.8) | 0.58% | — | HP PCAIAMI BiosAI | 15/7/2024 | 17/6/2026 | A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbitrary code execution. AMI has released firmware updates to mitigate this vulnerability. | |
| Modificada | Baja (1.9) | 0.38% | — | Zkteco Zkbiosecurity V5000 | 26/6/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scripting. It is possible to initiate the attack remotely. It is… | |
| Modificada | Baja (2) | 0.43% | — | Zkteco Zkbiosecurity V5000 | 15/6/2024 | 17/6/2026 | A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the argument Schedule Name leads to cross site scripting. The attack may be launched remotely. The… | |
| Modificada | Baja (2) | 0.43% | — | Zkteco Zkbiosecurity V5000 | 15/6/2024 | 17/6/2026 | A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Department Section. The manipulation of the argument Department Name leads to cross site scripting. The attack can be launched remotely. The… | |
| Aplazada | Alta (7.8) | 0.18% | — | Asustek Computer Asus Bios Flash DriverAI | 22/5/2024 | 17/6/2026 | An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests. | |
| Analizada | Media (6.7) | 0.37% | — | Intel TDX ModuleNetapp HCI Compute Node Bios | 16/5/2024 | 31/8/2026 | Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (8.2) | 0.38% | — | Intel TDX ModuleNetapp HCI Compute Node Bios | 16/5/2024 | 31/8/2026 | Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access. |