Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1334 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.17%—Intel Iflashv10/5/202317/6/2026
Uncontrolled search path in some Intel(R) NUC Chaco Canyon BIOS update software before version iFlashV Windows 5.13.00.2105 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)0.66%—Flashgames Project Flashgames5/3/202316/6/2026
A vulnerability was found in iGamingModules flashgames 1.1.0. It has been classified as critical. Affected is an unknown function of the file game.php. The manipulation of the argument lid leads to sql injection. It is possible to launch the attack remotely. The name of the patch is…
ModificadaMedia (5.5)0.31%💥 PoCIntel ONE Boot Flash Update16/2/202317/6/2026
Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (6.7)0.23%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+28330/1/202317/6/2026
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (4.4)0.20%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+32130/1/202317/6/2026
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
ModificadaAlta (8.7)0.81%—Jedec Universal Flash Storage23/1/202317/6/2026
Western Digital has identified a weakness in the UFS standard that could result in a security vulnerability. This vulnerability may exist in some systems where the Host boot ROM code implements the UFS Boot feature to boot from UFS compliant storage devices. The UFS Boot feature, as specified in the UFS standard, is…
AnalizadaAlta (7.5)3.6%💥 PoCLinux KernelNetapp E-series Santricity OS ControllerNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+2225/12/20215/8/2026
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
ModificadaAlta (8.8)8.9%—Flashget22/10/202117/6/2026
FlashGet v1.9.6 was discovered to contain a buffer overflow in the 'current path directory' function. This vulnerability allows attackers to elevate local process privileges via overwriting the registers.
ModificadaAlta (8.1)1.5%—IBM Spectrum VirtualizeIBM Spectrum Virtualize FOR Public CloudIBM Storwize V3500 SoftwareIBM Storwize V3700 Software+621/10/202117/6/2026
IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.
ModificadaMedia (5.4)0.50%—IBM Flashsystem 900 Firmware4/5/202117/6/2026
The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and prior and 1.6.1.2 and prior. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure…
ModificadaAlta (7.8)0.35%—AMD Vbios Flash Tool Software Development KIT12/11/202017/6/2026
A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated user to escalate privileges to NT authority system.
ModificadaAlta (8.8)4.3%—Adobe Flash Player14/10/202017/6/2026
Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL.
ModificadaAlta (8.1)1.6%—IBM Spectrum VirtualizeIBM Flashsystem V5000 FirmwareIBM Flashsystem V7200 FirmwareIBM Flashsystem V9000 Firmware+717/8/202017/6/2026
IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have access to. IBM X-Force ID: 186678.
ModificadaCrítica (9.8)7.6%—Adobe Flash Player Desktop RuntimeAdobe Flash Player12/6/202017/6/2026
Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, and Adobe Flash Player for Microsoft Edge and Internet Explorer 32.0.0.330 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (7.5)2.1%—NTPRedhat Enterprise LinuxNetapp Data OntapNetapp HCI Management Node+1317/4/202017/6/2026
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
ModificadaAlta (7.8)0.58%—Netapp Fabric-attached Storage 8700 FirmwareNetapp Fabric-attached Storage 8300 FirmwareNetapp ALL Flash Fabric-attached Storage A400 Firmware26/2/202017/6/2026
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
ModificadaMedia (5.5)0.28%—Lenovo Thinkcentre E93 FirmwareLenovo Thinkcentre M6500s FirmwareLenovo Thinkcentre M6500t FirmwareLenovo Thinkcentre M73p Firmware+17814/2/202017/6/2026
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.
ModificadaAlta (8.8)10%—Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation13/2/202017/6/2026
Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.6)8.8%💥 ExploitFlowplayer Flash8/2/202016/6/2026
Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.
ModificadaCrítica (9.6)1.8%—Irfanview Flashpix Plugin27/1/202016/6/2026
IrfanView FlashPix Plugin 4.3.4 0 has an Integer Overflow Vulnerability
ModificadaMedia (6.1)1.2%—Spreadshirt-rss-3d-cube-flash-gallery Project Spreadshirt-rss-3d-cube-flash-gallery2/1/202017/6/2026
Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attackers to execute arbitrary web script or HTML via unspecified parameters.
ModificadaMedia (6.1)2.5%💥 ExploitXorbin Analog Flash Clock27/12/201916/6/2026
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
ModificadaMedia (6.1)1.3%—Xorbin Digital Flash Clock27/12/201916/6/2026
WordPress Xorbin Digital Flash Clock 1.0 has XSS
ModificadaMedia (6.1)1.4%—Elvedia Flashcanvas22/11/201917/6/2026
Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header.
ModificadaMedia (6.7)0.38%💥 PoCNvidia GpumodeswitchNvidia NvflashNvidia Nvuflash18/11/201917/6/2026
NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys, nvflsh32.sys, and nvflsh64.sys) contains a vulnerability in which authenticated users with administrative privileges can gain access to device memory and registers of other devices not…