Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M15 Ryzen Edition R5 FirmwareDell Alienware M17 R5 AMD Firmware+79 | 1/2/2023 | 17/6/2026 | Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7) | 0.16% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R10 FirmwareDell Alienware Aurora R11 Firmware+235 | 1/2/2023 | 17/6/2026 | Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the system. | |
| Modificada | Media (5.1) | 0.16% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Chengming 3900 FirmwareDell G15 5510 Firmware+185 | 1/2/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Alta (7.1) | 0.21% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M15 Ryzen Edition R5 FirmwareDell Alienware M17 R5 AMD Firmware+79 | 1/2/2023 | 17/6/2026 | Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+283 | 30/1/2023 | 17/6/2026 | A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+321 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (6.5) | 0.30% | — | Cisco Webex Room Phone FirmwareCisco Webex Share FirmwareCisco SIP IP Phone Software | 20/1/2023 | 17/6/2026 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient resource allocation. An attacker… | |
| Modificada | Baja (3.5) | 0.31% | — | Siemens Simatic S7-1500 Software ControllerSiemens Simatic S7-plcsim AdvancedSiemens Simatic Wincc RuntimeSiemens 6es7154-8fb01-0ab0 Firmware+109 | 8/11/2022 | 17/6/2026 | The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack. | |
| Modificada | Media (6.8) | 0.48% | — | Sonos ONE Firmware | 20/10/2022 | 17/6/2026 | Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM. | |
| Modificada | Alta (7.8) | 0.24% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.8) | 0.24% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.8) | 0.21% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.8) | 0.21% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Media (4.4) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (4.4) | 0.17% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Alta (7.2) | 1.3% | — | Innovaphone Firmware | 30/9/2022 | 17/6/2026 | AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload. | |
| Modificada | Media (6.5) | 0.70% | — | Amperecomputing Ampere Altra MAX FirmwareAmperecomputing Ampere Altra FirmwareAmperecomputing Ampereone Firmware | 29/9/2022 | 17/6/2026 | Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with data being processed on the system. | |
| Modificada | Alta (7.8) | 0.22% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+395 | 6/9/2022 | 17/6/2026 | Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could exploit this vulnerability by sending malicious input via SMI to obtain arbitrary code execution during SMM. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+395 | 6/9/2022 | 17/6/2026 | Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI to bypass security checks resulting in arbitrary code execution in SMM. | |
| Modificada | Alta (7) | 0.14% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+395 | 6/9/2022 | 17/6/2026 | Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI in order to bypass security checks during SMM. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 FirmwareDell Chengming 3990 Firmware+395 | 6/9/2022 | 17/6/2026 | Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls. | |
| Modificada | Media (6.8) | 0.37% | — | Dell Chengming 3980 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G3 3579 Firmware+104 | 9/8/2022 | 17/6/2026 | Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system. | |
| Modificada | Alta (7.8) | 0.27% | — | Dell Alienware M15 R5 FirmwareDell G15 5515 FirmwareDell G5 SE 5505 FirmwareDell Inspiron 27 7775 Firmware+30 | 23/6/2022 | 17/6/2026 | Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM. |