Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.19% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+395 | 6/9/2022 | 17/6/2026 | Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI to bypass security checks resulting in arbitrary code execution in SMM. | |
| Modificada | Alta (7) | 0.14% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+395 | 6/9/2022 | 17/6/2026 | Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI in order to bypass security checks during SMM. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+395 | 6/9/2022 | 17/6/2026 | Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls. | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+42 | 11/3/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+42 | 11/3/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+42 | 11/3/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+42 | 11/3/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Alienware 13 R3 FirmwareDell Alienware 15 R3 FirmwareDell Alienware 15 R4 FirmwareDell Alienware 17 R4 Firmware+42 | 11/3/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | |
| Modificada | Media (4.4) | 0.29% | — | Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 Firmware+350 | 10/6/2020 | 17/6/2026 | Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default… | |
| Modificada | Media (4.4) | 0.25% | — | Dell G3 3579 FirmwareDell G3 3779 FirmwareDell G3 15 3590 FirmwareDell G5 15 5590 Firmware+109 | 21/2/2020 | 17/6/2026 | Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit… | |
| Modificada | Alta (7.8) | 7.1% | — | HP Hspa+ Gobi 4GHP Lt4112 LTEHP Elite X2 1010 G2HP Elitebook 1040 G1+35 | 27/8/2015 | 17/6/2026 | The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows remote attackers to modify data or cause a denial of service, or execute arbitrary code, via unspecified vectors. | |
| Modificada | Media (6.9) | 0.51% | — | HP Hspa+ Gobi 4GHP Lt4112 LTEHP Elite X2 1010 G2HP Elitebook 1040 G1+35 | 27/8/2015 | 17/6/2026 | The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows local users to gain privileges via unspecified vectors. | |
| Modificada | Alta (9.3) | 32% | 💥 Exploit | Advantech StudioIndusoft Thin ClientIndusoft WEB Studio | 4/5/2011 | 16/6/2026 | Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long… | |
| Modificada | Media (5) | 1.4% | — | Devonit Thin-client Management Tool | 25/8/2010 | 16/6/2026 | The DevonIT thin-client management tool relies on a shared secret for authentication but transmits the secret in cleartext, which makes it easier for remote attackers to discover the secret value, and consequently obtain administrative control over client machines, by sniffing the network. | |
| Modificada | Alta (7.5) | 2.4% | — | Devonit Thin-client Management Tool | 25/8/2010 | 16/6/2026 | Buffer overflow in tm-console-bin in the DevonIT thin-client management tool might allow remote attackers to execute arbitrary code via unspecified vectors. |