Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.19%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaAlta (7.8)0.16%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM.
ModificadaAlta (7.8)0.24%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaAlta (7.8)0.24%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaAlta (7.8)0.21%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaAlta (7.8)0.21%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
ModificadaMedia (4.4)0.17%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
ModificadaMedia (4.4)0.17%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+28612/10/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
ModificadaAlta (8.8)0.94%—Siemens 6gk6108-4am00-2ba2 FirmwareSiemens 6gk6108-4am00-2da2 FirmwareSiemens 6gk5804-0ap00-2aa2 FirmwareSiemens 6gk5812-1aa00-2aa2 Firmware+18211/10/202217/6/2026
Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges.
ModificadaMedia (4.9)0.45%—IBM Power System Ac922 (8335-gtg) FirmwareIBM Power System Ac922 (8335-gtx) FirmwareIBM Power System Ac922 (8335-gth) FirmwareIBM Hardware Management Console 7063-cr2 Firmware22/8/202217/6/2026
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221.
ModificadaMedia (4.8)0.96%—Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance Sc-600 FirmwareSiemens Scalance Sc622-2c Firmware+8610/8/202217/6/2026
Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.
ModificadaAlta (7.5)1.7%—Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance W700 Ieee 802.11ax FirmwareSiemens Scalance W700 Ieee 802.11n Firmware+8010/8/202217/6/2026
Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack.
ModificadaAlta (7.2)1.8%—Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance Sc-600 FirmwareSiemens Scalance Sc622-2c Firmware+8610/8/202217/6/2026
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.
ModificadaAlta (7.5)0.62%—Siemens Scalance Xm408-4c FirmwareSiemens Scalance Xm408-4c L3 FirmwareSiemens Scalance Xm408-8c FirmwareSiemens Scalance Xm408-8c L3 Firmware+1314/6/202217/6/2026
A vulnerability has been identified in SCALANCE XM408-4C (All versions < V6.5), SCALANCE XM408-4C (L3 int.) (All versions < V6.5), SCALANCE XM408-8C (All versions < V6.5), SCALANCE XM408-8C (L3 int.) (All versions < V6.5), SCALANCE XM416-4C (All versions < V6.5), SCALANCE XM416-4C (L3 int.) (All versions < V6.5),…
ModificadaMedia (6.5)0.60%—Siemens Desigo Dxr2 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc5 Firmware20/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The application, after a successful login, sets the session cookie on the browser via…
ModificadaAlta (7.5)0.90%—Siemens Desigo Dxr2 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc5 Firmware20/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application does not employ any countermeasures against…
ModificadaMedia (5.3)1.1%—Siemens Desigo Dxr2 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc5 Firmware20/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application fails to normalize the response times of…
ModificadaCrítica (9.1)0.98%—Siemens Desigo Pxc5 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Dxr2 Firmware10/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application returns an AuthToken that does not expire at the defined auto logoff…
ModificadaMedia (6.5)0.48%—Siemens Desigo Pxc5 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Dxr2 Firmware10/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application stores the PBKDF2 derived key of users passwords with a low…
ModificadaMedia (6.5)0.85%—Siemens Desigo Pxc5 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Dxr2 Firmware10/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application fails to enforce an upper bound to the cost factor of the PBKDF2…
ModificadaAlta (7.5)0.93%—Siemens Desigo Dxr2 FirmwareSiemens Desigo Pxc3 FirmwareSiemens Desigo Pxc4 FirmwareSiemens Desigo Pxc5 Firmware10/5/202217/6/2026
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). When the controller receives a specific BACnet protocol packet, an exception causes the…
ModificadaAlta (7.8)0.29%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+4211/3/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
ModificadaAlta (7.8)0.29%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+4211/3/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
ModificadaAlta (7.8)0.29%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+4211/3/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
ModificadaAlta (7.8)0.29%—Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+4211/3/202217/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.