Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.42% | — | HP Elite Dragonfly FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX FirmwareHP Elite X2 1013 G3 Firmware+183 | 16/2/2022 | 17/6/2026 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.45% | — | HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+183 | 16/2/2022 | 17/6/2026 | A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware. | |
| Modificada | Alta (8.8) | 0.44% | — | HP 260 G3 Desktop Mini PC FirmwareHP Elitedesk 800 35W G4 Desktop Mini PC FirmwareHP Elitedesk 800 65W G4 Desktop Mini PC FirmwareHP Elitedesk 800 95W G4 Desktop Mini PC Firmware+183 | 16/2/2022 | 17/6/2026 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution. | |
| Modificada | Media (5.5) | 0.23% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+20 | 11/2/2022 | 17/6/2026 | Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health… | |
| Modificada | Crítica (9.8) | 2.4% | — | Windriver VxworksSiemens Ruggedcom WIN Subscriber Station FirmwareSiemens Scalance X200-4 P IRT FirmwareSiemens Scalance X201-3p IRT Firmware+32 | 13/4/2021 | 17/6/2026 | An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client. | |
| Modificada | Alta (7.5) | 1.8% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | A null pointer dereference was addressed with improved input validation. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause a system denial of service. | |
| Modificada | Crítica (9.8) | 1.8% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to leak memory. | |
| Modificada | Alta (7.5) | 1.1% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | Source-routed IPv4 packets were disabled by default. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. Source-routed IPv4 packets may be unexpectedly accepted. | |
| Modificada | Crítica (9.8) | 2.7% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause arbitrary code execution. | |
| Modificada | Alta (7.5) | 1.2% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | The issue was addressed with improved data deletion. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A base station factory reset may not delete all user information. | |
| Modificada | Crítica (9.8) | 2.7% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | A null pointer dereference was addressed with improved input validation. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause arbitrary code execution. | |
| Modificada | Media (6.5) | 1.1% | — | Apple Airport Base Station Firmware | 27/10/2020 | 17/6/2026 | A denial of service issue was addressed with improved memory handling. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. An attacker in a privileged position may be able to perform a denial of service attack. | |
| Modificada | Alta (8.8) | 0.28% | — | Bosch Recording Station Firmware | 27/5/2020 | 17/6/2026 | Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk Mode and access the underlying operating system. | |
| Modificada | Media (6.8) | 0.43% | — | GE Vivid E95 FirmwareGE Vivid E90 FirmwareGE Vivid S70n FirmwareGE Vivid T8 Firmware+12 | 20/2/2020 | 17/6/2026 | A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products:… | |
| Modificada | Media (6.8) | 0.60% | — | HP Elitedesk 800 G5 DM FirmwareHP Elitedesk 800 G5 SFF FirmwareHP Elitedesk 800 G5 TWR FirmwareHP Eliteone 800 G5 AIO Firmware+29 | 31/1/2020 | 17/6/2026 | A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks. This industry-wide issue requires physically accessing internal expansion slots with specialized hardware and software tools to modify UEFI code in memory. This affects HP Intel-based Business PCs… | |
| Modificada | Media (5.3) | 1.7% | — | BD Alaris Gateway Workstation Firmware | 13/6/2019 | 17/6/2026 | BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Workstation terminal to gain access to the status and configuration information of… | |
| Modificada | Crítica (10) | 2.5% | — | BD Alaris Gateway Workstation FirmwareBD Alaris GS Syringe Pump FirmwareBD Alaris GH Syringe Pump FirmwareBD Alaris CC Syringe Pump Firmware+1 | 13/6/2019 | 17/6/2026 | BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the latest firmware Versions 1.3.2 and 1.6.1, Additionally, the following products using software Version 2.3.6 and below, Alaris GS, Alaris GH, Alaris CC, Alaris TIVA, The… | |
| Modificada | Media (6.8) | 1.2% | — | HP Z4 G4 Workstation FirmwareHP Z4 G4 Core-x Workstation FirmwareHP Z6 G4 Workstation FirmwareHP Z8 G4 Workstation Firmware | 29/5/2019 | 17/6/2026 | HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is enabled by default. | |
| Modificada | Alta (7.2) | 1.4% | — | HP Z4 G4 Workstation FirmwareHP Z4 G4 Core-x Workstation FirmwareHP Z6 G4 Workstation FirmwareHP Z8 G4 Workstation Firmware | 29/5/2019 | 17/6/2026 | HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is disabled by default. | |
| Modificada | Crítica (9.8) | 2.6% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Cp5525 FirmwareHP Color Laserjet Enterprise M553 FirmwareHP Color Laserjet Enterprise M552 Firmware+139 | 11/4/2019 | 17/6/2026 | HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient solution bundle signature validation that potentially allows execution of arbitrary code. | |
| Modificada | Crítica (9.8) | 2.6% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Cp5525 FirmwareHP Color Laserjet Enterprise Flow MFP M681f FirmwareHP Color Laserjet Enterprise Flow MFP M681z Firmware+134 | 27/3/2019 | 17/6/2026 | In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code. | |
| Modificada | Media (5.5) | 0.67% | — | HP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 FirmwareHP Proliant Xl750f Gen9 Server Firmware+97 | 3/12/2018 | 17/6/2026 | The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system ROM updates which also addressed the… | |
| Modificada | Crítica (9.8) | 2.1% | — | Schneider-electric Evlink Charging Station Firmware | 3/7/2018 | 17/6/2026 | In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may allow a remote attacker to gain administrative privileges without properly authenticating remote users. | |
| Modificada | Alta (7.8) | 1.2% | — | Kddi QUA Station Firmware | 18/8/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer of Qua station connection tool for Windows version 1.00.03 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (6.1) | 0.95% | — | Bbraun Station Firmware | 30/6/2017 | 17/6/2026 | An open redirect issue was discovered in B. Braun Medical SpaceCom module, which is integrated into the SpaceStation docking station: SpaceStation with SpaceCom module (integrated as part number 8713142U), software versions prior to Version 012U000040, and SpaceStation (part number 8713140U) with installed SpaceCom… |