Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1334 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.17% | — | Intel Iflashv | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) NUC Chaco Canyon BIOS update software before version iFlashV Windows 5.13.00.2105 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 0.66% | — | Flashgames Project Flashgames | 5/3/2023 | 16/6/2026 | A vulnerability was found in iGamingModules flashgames 1.1.0. It has been classified as critical. Affected is an unknown function of the file game.php. The manipulation of the argument lid leads to sql injection. It is possible to launch the attack remotely. The name of the patch is… | |
| Modificada | Media (5.5) | 0.31% | 💥 PoC | Intel ONE Boot Flash Update | 16/2/2023 | 17/6/2026 | Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+283 | 30/1/2023 | 17/6/2026 | A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+321 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Alta (8.7) | 0.81% | — | Jedec Universal Flash Storage | 23/1/2023 | 17/6/2026 | Western Digital has identified a weakness in the UFS standard that could result in a security vulnerability. This vulnerability may exist in some systems where the Host boot ROM code implements the UFS Boot feature to boot from UFS compliant storage devices. The UFS Boot feature, as specified in the UFS standard, is… | |
| Analizada | Alta (7.5) | 3.6% | 💥 PoC | Linux KernelNetapp E-series Santricity OS ControllerNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+22 | 25/12/2021 | 5/8/2026 | In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses. | |
| Modificada | Alta (8.8) | 8.9% | — | Flashget | 22/10/2021 | 17/6/2026 | FlashGet v1.9.6 was discovered to contain a buffer overflow in the 'current path directory' function. This vulnerability allows attackers to elevate local process privileges via overwriting the registers. | |
| Modificada | Alta (8.1) | 1.5% | — | IBM Spectrum VirtualizeIBM Spectrum Virtualize FOR Public CloudIBM Storwize V3500 SoftwareIBM Storwize V3700 Software+6 | 21/10/2021 | 17/6/2026 | IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Flashsystem 900 Firmware | 4/5/2021 | 17/6/2026 | The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and prior and 1.6.1.2 and prior. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure… | |
| Modificada | Alta (7.8) | 0.35% | — | AMD Vbios Flash Tool Software Development KIT | 12/11/2020 | 17/6/2026 | A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated user to escalate privileges to NT authority system. | |
| Modificada | Alta (8.8) | 4.3% | — | Adobe Flash Player | 14/10/2020 | 17/6/2026 | Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL. | |
| Modificada | Alta (8.1) | 1.6% | — | IBM Spectrum VirtualizeIBM Flashsystem V5000 FirmwareIBM Flashsystem V7200 FirmwareIBM Flashsystem V9000 Firmware+7 | 17/8/2020 | 17/6/2026 | IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have access to. IBM X-Force ID: 186678. | |
| Modificada | Crítica (9.8) | 7.6% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 12/6/2020 | 17/6/2026 | Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, and Adobe Flash Player for Microsoft Edge and Internet Explorer 32.0.0.330 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.5) | 2.1% | — | NTPRedhat Enterprise LinuxNetapp Data OntapNetapp HCI Management Node+13 | 17/4/2020 | 17/6/2026 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp. | |
| Modificada | Alta (7.8) | 0.58% | — | Netapp Fabric-attached Storage 8700 FirmwareNetapp Fabric-attached Storage 8300 FirmwareNetapp ALL Flash Fabric-attached Storage A400 Firmware | 26/2/2020 | 17/6/2026 | NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access. | |
| Modificada | Media (5.5) | 0.28% | — | Lenovo Thinkcentre E93 FirmwareLenovo Thinkcentre M6500s FirmwareLenovo Thinkcentre M6500t FirmwareLenovo Thinkcentre M73p Firmware+178 | 14/2/2020 | 17/6/2026 | Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled. | |
| Modificada | Alta (8.8) | 10% | — | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 13/2/2020 | 17/6/2026 | Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.6) | 8.8% | 💥 Exploit | Flowplayer Flash | 8/2/2020 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin. | |
| Modificada | Crítica (9.6) | 1.8% | — | Irfanview Flashpix Plugin | 27/1/2020 | 16/6/2026 | IrfanView FlashPix Plugin 4.3.4 0 has an Integer Overflow Vulnerability | |
| Modificada | Media (6.1) | 1.2% | — | Spreadshirt-rss-3d-cube-flash-gallery Project Spreadshirt-rss-3d-cube-flash-gallery | 2/1/2020 | 17/6/2026 | Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attackers to execute arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Media (6.1) | 2.5% | 💥 Exploit | Xorbin Analog Flash Clock | 27/12/2019 | 16/6/2026 | Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS | |
| Modificada | Media (6.1) | 1.3% | — | Xorbin Digital Flash Clock | 27/12/2019 | 16/6/2026 | WordPress Xorbin Digital Flash Clock 1.0 has XSS | |
| Modificada | Media (6.1) | 1.4% | — | Elvedia Flashcanvas | 22/11/2019 | 17/6/2026 | Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header. | |
| Modificada | Media (6.7) | 0.38% | 💥 PoC | Nvidia GpumodeswitchNvidia NvflashNvidia Nvuflash | 18/11/2019 | 17/6/2026 | NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys, nvflsh32.sys, and nvflsh64.sys) contains a vulnerability in which authenticated users with administrative privileges can gain access to device memory and registers of other devices not… |