Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.7) | 0.12% | — | Intel Aptio V Uefi Firmware Integrator Tools | 14/11/2023 | 17/6/2026 | Race condition in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.21% | — | Intel Aptio V Uefi Firmware Integrator Tools | 14/11/2023 | 17/6/2026 | Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (6.7) | 0.21% | — | Intel Aptio V Uefi Firmware Integrator Tools | 14/11/2023 | 17/6/2026 | Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Intel Aptio V Uefi Firmware Integrator Tools | 14/11/2023 | 17/6/2026 | Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.17% | — | Nvidia Bluefield 1 FirmwareNvidia Bluefield 2 LTS FirmwareNvidia Bluefield 2 GA FirmwareNvidia Bluefield 3 GA Firmware | 12/9/2023 | 17/6/2026 | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrect user management error. A successful exploit of this vulnerability may lead to escalation of privileges. | |
| Modificada | Media (6.7) | 0.28% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.26% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.60% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+1 | 11/8/2023 | 17/6/2026 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.42% | — | Intel Killer Wifi SoftwareIntel Proset/wireless WifiIntel Uefi Wifi DriverIntel Killer Wi-fi 6 Ax1650 Firmware+338 | 11/11/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (6.7) | 0.85% | 💥 PoC | Eurosoft-uk Uefi BootloaderRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+6 | 26/8/2022 | 17/6/2026 | A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader.… | |
| Modificada | Media (6.7) | 1.1% | 💥 PoC | Horizondatasys Uefi BootloaderRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+6 | 26/8/2022 | 17/6/2026 | A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this… | |
| Modificada | Alta (8.8) | 0.69% | — | Intel Uefi Wifi Driver | 9/2/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Crítica (9.8) | 1.4% | — | Insydeh2o Uefi Bios | 3/11/2021 | 17/6/2026 | An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges. | |
| Modificada | Alta (7.8) | 1.3% | 💥 Exploit | Asrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled | 30/10/2018 | 17/6/2026 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated… | |
| Modificada | Alta (7.8) | 1.5% | 💥 Exploit | Asrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled | 30/10/2018 | 17/6/2026 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code. | |
| Modificada | Alta (7.1) | 0.98% | 💥 Exploit | Asrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled | 30/10/2018 | 17/6/2026 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. | |
| Modificada | Alta (7.8) | 1.2% | 💥 Exploit | Asrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled | 30/10/2018 | 17/6/2026 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write CR register values. This could be leveraged in a number of ways to ultimately run code with elevated… | |
| Modificada | Baja (2.1) | 0.80% | — | IBM Uefi | 28/6/2015 | 17/6/2026 | IBM Unified Extensible Firmware Interface (UEFI) on Flex System x880 X6, System x3850 X6, and System x3950 X6 devices allows remote authenticated users to cause an unspecified temporary denial of service by using privileged access to enable a legacy boot mode. | |
| Modificada | Media (5) | 2.5% | — | Frees WANApple MAC OS XApple MAC OS X ServerFreebsd+8 | 4/11/2002 | 16/6/2026 | IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors. |