Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

96 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.7)0.12%—Intel Aptio V Uefi Firmware Integrator Tools14/11/202317/6/2026
Race condition in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.21%—Intel Aptio V Uefi Firmware Integrator Tools14/11/202317/6/2026
Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (6.7)0.21%—Intel Aptio V Uefi Firmware Integrator Tools14/11/202317/6/2026
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.18%—Intel Aptio V Uefi Firmware Integrator Tools14/11/202317/6/2026
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.17%—Nvidia Bluefield 1 FirmwareNvidia Bluefield 2 LTS FirmwareNvidia Bluefield 2 GA FirmwareNvidia Bluefield 3 GA Firmware12/9/202317/6/2026
NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrect user management error. A successful exploit of this vulnerability may lead to escalation of privileges.
ModificadaMedia (6.7)0.28%—Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+111/8/202317/6/2026
Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.24%—Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+111/8/202317/6/2026
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.26%—Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+111/8/202317/6/2026
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.60%—Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+111/8/202317/6/2026
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (6.7)0.24%—Intel KillerIntel Proset/wireless WifiIntel Uefi FirmwareFedoraproject Fedora+111/8/202317/6/2026
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.42%—Intel Killer Wifi SoftwareIntel Proset/wireless WifiIntel Uefi Wifi DriverIntel Killer Wi-fi 6 Ax1650 Firmware+33811/11/202217/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access.
ModificadaMedia (6.7)0.85%💥 PoCEurosoft-uk Uefi BootloaderRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+626/8/202217/6/2026
A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader.…
ModificadaMedia (6.7)1.1%💥 PoCHorizondatasys Uefi BootloaderRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+626/8/202217/6/2026
A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this…
ModificadaAlta (8.8)0.69%—Intel Uefi Wifi Driver9/2/202217/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
ModificadaCrítica (9.8)1.4%—Insydeh2o Uefi Bios3/11/202117/6/2026
An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges.
ModificadaAlta (7.8)1.3%💥 ExploitAsrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated…
ModificadaAlta (7.8)1.5%💥 ExploitAsrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.
ModificadaAlta (7.1)0.98%💥 ExploitAsrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
ModificadaAlta (7.8)1.2%💥 ExploitAsrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write CR register values. This could be leveraged in a number of ways to ultimately run code with elevated…
ModificadaBaja (2.1)0.80%—IBM Uefi28/6/201517/6/2026
IBM Unified Extensible Firmware Interface (UEFI) on Flex System x880 X6, System x3850 X6, and System x3950 X6 devices allows remote authenticated users to cause an unspecified temporary denial of service by using privileged access to enable a legacy boot mode.
ModificadaMedia (5)2.5%—Frees WANApple MAC OS XApple MAC OS X ServerFreebsd+84/11/200216/6/2026
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
Orbitaley — Vulnerabilidades