Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is especially problematic if you use Default DESFire… | |
| Modificada | Crítica (9.8) | 1.1% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some attributes to check. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device | |
| Modificada | Crítica (9.8) | 1.1% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | The handler of the retrofit validation command doesn't properly check the boundaries when performing certain validation operations. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device | |
| Modificada | Crítica (9.8) | 1.1% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. This could potentially lead to a Remote Code execution on the targeted device. | |
| Modificada | Alta (7.5) | 0.68% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the terminal. the only way to recover the terminal is by sending back the terminal to the manufacturer | |
| Modificada | Media (4.8) | 0.42% | — | Idemia Sgima Lite & Lite+ FirmwareIdemia Sigma Wide FirmwareIdemia Sigma Extreme FirmwareIdemia Morphowave Compact Firmware+2 | 28/11/2023 | 17/6/2026 | The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface. The root cause of the vulnerability is inadequate input validation and… | |
| Modificada | Media (5.3) | 0.20% | — | Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 20/11/2023 | 17/6/2026 | Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges. | |
| Modificada | Crítica (9.8) | 0.81% | — | Contec Solarview Compact Firmware | 27/10/2023 | 17/6/2026 | An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component. | |
| Modificada | Baja (2.7) | 0.47% | — | Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 17/10/2023 | 17/6/2026 | On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected. | |
| Modificada | Alta (7.5) | 3.2% | — | Contec Solarview Compact Firmware | 8/9/2023 | 17/6/2026 | SolarView Compact < 6.00 is vulnerable to Directory Traversal. | |
| Modificada | Baja (3.9) | 0.24% | — | Dell Alienware M15 R7 FirmwareDell Alienware M16 FirmwareDell Alienware M18 FirmwareDell Chengming 3900 Firmware+107 | 16/8/2023 | 17/6/2026 | Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may potentially exploit this vulnerability in order to modify a security-critical UEFI variable without knowledge of the BIOS administrator. | |
| Modificada | Media (6.3) | 0.19% | — | Dell Alienware M15 R7 FirmwareDell Alienware M16 FirmwareDell Alienware M18 FirmwareDell Chengming 3900 Firmware+238 | 16/8/2023 | 17/6/2026 | Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+430 | 23/6/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable. |