Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.30% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.30% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.30% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Insufficient control flow management in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.30% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.24% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access. | |
| Modificada | Media (4.4) | 0.25% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access. | |
| Modificada | Alta (7.8) | 0.33% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Improper access control in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (5.1) | 0.14% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware M15 R3 FirmwareDell Alienware M15 R4 Firmware+210 | 9/2/2022 | 17/6/2026 | Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware. | |
| Modificada | Alta (7.2) | 0.26% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware M15 R3 FirmwareDell Alienware M15 R4 Firmware+210 | 9/2/2022 | 17/6/2026 | Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device. | |
| Modificada | Media (5.9) | 0.42% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+2 | 23/11/2021 | 17/6/2026 | There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected product versions include: IPS Module… | |
| Modificada | Alta (7.5) | 0.68% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6600 FirmwareHuawei S12700 Firmware+7 | 27/10/2021 | 17/6/2026 | There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected product versions include:IPS Module… | |
| Modificada | Media (6.7) | 0.25% | — | Dell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G3 15 3500 FirmwareDell G3 15 3590 Firmware+81 | 28/9/2021 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Media (6.7) | 0.27% | — | Intel Atom C3000Intel Atom C3308Intel Atom C3336Intel Atom C3338+1060 | 16/8/2021 | 17/6/2026 | Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 3.7% | — | Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 Firmware | 22/7/2021 | 17/6/2026 | An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. The device by default has a TELNET interface available (which is not advertised or functionally used, but is nevertheless available). Two backdoor accounts (root and default) exist that can be used on this interface. The… | |
| Modificada | Media (6.7) | 0.33% | — | Intel Atom C3000Intel Atom C3308Intel Atom C3336Intel Atom C3338+1060 | 14/7/2021 | 17/6/2026 | Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 0.29% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions. | |
| Modificada | Alta (7.5) | 0.28% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions. | |
| Modificada | Alta (7.5) | 0.26% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions. | |
| Modificada | Media (6.5) | 0.54% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering. | |
| Modificada | Media (4.9) | 0.56% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Semg9811 FirmwareHuawei Usg9500 Firmware | 22/6/2021 | 17/6/2026 | There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include: IPS Module versions V500R005C00,… | |
| Modificada | Media (6.5) | 0.58% | — | Huawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 FirmwareHuawei Secospace Usg6600 Firmware+1 | 27/5/2021 | 17/6/2026 | There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers can exploit this vulnerability by performing multiple abnormal activities to trigger the bad logic and cause out-of-bounds write. This may compromise the normal service of the… | |
| Modificada | Media (4.9) | 0.64% | — | Huawei Usg9500 Firmware | 27/5/2021 | 17/6/2026 | There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500. An authentication attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the… | |
| Modificada | Crítica (9.8) | 1.6% | — | Zebra Fx9500 Firmware | 11/5/2021 | 17/6/2026 | An issue was discovered on Zebra (formerly Motorola Solutions) Fixed RFID Reader FX9500 devices. An unauthenticated attacker can upload arbitrary files to the filesystem that can then be accessed through the web interface. This can lead to information disclosure and code execution. NOTE: This vulnerability only… | |
| Modificada | Media (6.5) | 0.83% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+8 | 8/4/2021 | 17/6/2026 | There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions… | |
| Modificada | Alta (7.8) | 0.35% | — | Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 Firmware | 2/4/2021 | 17/6/2026 | An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "default" account is capable of reading the /etc/passwd file, which contains a weakly hashed root password. By taking this hash and cracking it, the attacker can obtain root rights on the device. |