Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
226 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.25% | — | Dell Vxrail D560 FirmwareDell Vxrail D560f FirmwareDell Vxrail E460 FirmwareDell Vxrail E560 Firmware+41 | 23/6/2023 | 17/6/2026 | Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim’s… | |
| Modificada | Alta (7.5) | 0.46% | — | Dell Vxrail D560 FirmwareDell Vxrail D560f FirmwareDell Vxrail E460 FirmwareDell Vxrail E560 Firmware+41 | 23/6/2023 | 17/6/2026 | Dell VxRail, version(s) 8.0.100 and earlier contain a denial-of-service vulnerability in the upgrade functionality. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to degraded performance and system malfunction. | |
| Modificada | Alta (8.8) | 0.51% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 1/5/2023 | 17/6/2026 | A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API. | |
| Modificada | Alta (8.8) | 0.57% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 1/5/2023 | 17/6/2026 | A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call. | |
| Modificada | Media (5.9) | 0.45% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined. | |
| Modificada | Media (4.9) | 0.57% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured | |
| Modificada | Media (6.5) | 0.36% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions. | |
| Modificada | Alta (8.8) | 0.50% | — | Lenovo Thinkagile Hx5530 FirmwareLenovo Thinkagile Hx7530 FirmwareLenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Firmware+105 | 28/4/2023 | 17/6/2026 | A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”. | |
| Modificada | Media (6.5) | 0.46% | — | Schneider-electric Netbotz 355 FirmwareSchneider-electric Netbotz 450 FirmwareSchneider-electric Netbotz 455 FirmwareSchneider-electric Netbotz 550 Firmware+1 | 18/4/2023 | 17/6/2026 | A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user to be tricked into performing unintended actions when external address frames are not properly restricted. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior) | |
| Modificada | Alta (7.5) | 0.63% | — | Schneider-electric Netbotz 355 FirmwareSchneider-electric Netbotz 450 FirmwareSchneider-electric Netbotz 455 FirmwareSchneider-electric Netbotz 550 Firmware+1 | 18/4/2023 | 17/6/2026 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover when a brute force attack is performed on the account. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior) | |
| Modificada | Media (6.1) | 0.38% | — | Schneider-electric Netbotz 355 FirmwareSchneider-electric Netbotz 450 FirmwareSchneider-electric Netbotz 455 FirmwareSchneider-electric Netbotz 550 Firmware+1 | 18/4/2023 | 17/6/2026 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior) | |
| Modificada | Alta (7.5) | 0.89% | 💥 PoC | Ieee 802.11Sonicwall Tz670 FirmwareSonicwall Tz570 FirmwareSonicwall Tz570p Firmware+26 | 15/4/2023 | 17/6/2026 | The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or… | |
| Modificada | Media (4.6) | 0.29% | — | Dell Inspiron 14 Plus 7420 FirmwareDell Inspiron 14 Plus 7620 FirmwareDell Inspiron 3511 FirmwareDell Inspiron 3520 Firmware+71 | 8/3/2023 | 17/6/2026 | Dell BIOS contains an Improper Authorization vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Media (4.2) | 0.17% | — | Dell Alienware 13 R2 FirmwareDell Alienware 13 R3 FirmwareDell Alienware 15 R2 FirmwareDell Alienware 15 R3 Firmware+153 | 10/2/2023 | 17/6/2026 | Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces. | |
| Modificada | Alta (7) | 0.16% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R10 FirmwareDell Alienware Aurora R11 Firmware+235 | 1/2/2023 | 17/6/2026 | Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the system. | |
| Modificada | Media (5.1) | 0.16% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Chengming 3900 FirmwareDell G15 5510 Firmware+185 | 1/2/2023 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+321 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (4.3) | 0.41% | — | Lenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile Hx1021 FirmwareLenovo Thinkagile Hx1320 Firmware+94 | 30/1/2023 | 17/6/2026 | The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect. | |
| Modificada | Media (6.5) | 0.63% | — | Lenovo Thinkagile Vx3331 FirmwareLenovo Thinkagile HX Enclosure Certified Node FirmwareLenovo Thinkagile Hx1021 FirmwareLenovo Thinkagile Hx1320 Firmware+94 | 30/1/2023 | 17/6/2026 | A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service. | |
| Modificada | Alta (7.8) | 0.21% | — | Lenovo Ideacentre 510-15ikl FirmwareLenovo Ideacentre 510s-08ikl FirmwareLenovo Ideacentre 300s-11ish FirmwareLenovo Ideacentre 310-15asr Firmware+132 | 26/12/2022 | 17/6/2026 | Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading. | |
| Modificada | Alta (7.5) | 1.5% | — | Rockwellautomation Compactlogix 5370 FirmwareRockwellautomation Compact Guardlogix 5370 FirmwareRockwellautomation Compact Guardlogix 5380 FirmwareRockwellautomation Controllogix 5570 Firmware+2 | 16/12/2022 | 17/6/2026 | A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS). | |
| Modificada | Alta (7.2) | 3.3% | — | Sharp Bp-30c25 FirmwareSharp Bp-30c25t FirmwareSharp Bp-30c25y FirmwareSharp Bp-30c25z Firmware+154 | 16/12/2022 | 17/6/2026 | Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earlier, 121 or earlier, 500 or earlier, 402 or earlier, 790 or earlier, and Digital Multifunctional System (Monochrome) 200 or earlier, 211 or… | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM. | |
| Modificada | Alta (7.8) | 0.24% | — | Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 Firmware+286 | 12/10/2022 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. |