Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

230 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.5%—Bytemark Symbiosis27/1/202017/6/2026
Bytemark Symbiosis allows remote attackers to cause a denial of service via a crafted username, which triggers the firewall to blacklist the IP.
ModificadaAlta (8.8)19%—Supermicro X8sti-f BiosSupermicro X8sti-f Firmware8/12/201917/6/2026
On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires a POST to /rpc/setvmdrive.asp with shell metacharacters in ShareHost or ShareName. The attacker…
ModificadaAlta (7.8)0.32%—Intel BiosIntel Ayaplcel.86aIntel Bnkbl357.86aIntel Ccsklm30.86a+1410/5/201817/6/2026
Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate privileges to System Management Mode (SMM).
ModificadaMedia (6.4)0.27%—Lenovo Flex System X240 M5 BiosLenovo Flex System X280 X6 BiosLenovo Flex System X480 X6 BiosLenovo Flex System X880 Bios+74/5/201817/6/2026
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.
ModificadaAlta (7.8)0.38%—Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+14418/8/201717/6/2026
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.
ModificadaCrítica (9)1.4%—Intel Nuc7i3bnk BiosIntel Nuc7i5bnk BiosIntel Nuc7i7bnh BiosIntel Stk2mv64cc Bios+1826/7/201717/6/2026
Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows compromised system firmware to impact SGX security via incorrect early system state.
ModificadaMedia (6.7)0.34%—Lenovo Bios17/7/201717/6/2026
Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.
ModificadaBaja (3.9)0.30%—Intel Nuc6i3syh BiosIntel Nuc6i3syk Bios3/4/201717/6/2026
The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version SY0059 may allow may allow an attacker with physical access to the system to gain access to personal information.
ModificadaBaja (3.9)0.32%—Intel Nuc6i7kyk Bios3/4/201717/6/2026
The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version KY0045 may allow may allow an attacker with physical access to the system to gain access to personal information.
ModificadaBaja (3.9)0.30%—Intel Stk2mv64cc Bios3/4/201717/6/2026
The BIOS in Intel Compute Stick systems based on 6th Gen Intel Core processors prior to version CC047 may allow an attacker with physical access to the system to gain access to personal information.
ModificadaMedia (4.9)0.92%—Lenovo Flex System X240 M5 BiosLenovo Flex System X280 M6 BiosLenovo Flex System X480 X6 BiosLenovo Flex System X880 X6 Bios+726/1/201717/6/2026
The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure.
ModificadaMedia (6.7)0.31%—Intel City BiosIntel Canyon BiosIntel Swift Canyon BiosIntel Citry Bios8/12/201617/6/2026
SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.
ModificadaMedia (4.4)0.30%—Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+7030/11/201617/6/2026
A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be…
ModificadaMedia (4.4)0.30%—Lenovo BiosLenovo Notebook 110 14ibr BiosLenovo Notebook 110 15ibr BiosLenovo Notebook B70 80 Bios+2529/11/201617/6/2026
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.
ModificadaAlta (7.8)0.38%—Lenovo Bios22/9/201617/6/2026
The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer RQ940, RS140, TS140, TS240, TS440, and TS540 devices; and ThinkStation E32, P300, and P310 devices might allow local users or physically proximate attackers to bypass…
ModificadaAlta (8.2)0.39%—Lenovo Bios EFI Driver30/6/201617/6/2026
Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.
ModificadaMedia (6)1.1%—Dell Bios1/8/201517/6/2026
The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks…
ModificadaMedia (5)1.5%—Bytemark Symbiosis13/8/201216/6/2026
Bytemark Symbiosis before Revision 1322 does not properly validate passwords, which allows remote attackers to gain access to email accounts via an arbitrary password.
ModificadaMedia (6.9)0.32%—Intel Bios27/8/200916/6/2026
Intel Desktop and Intel Mobile Boards with BIOS firmware DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, MGM965TW, D945GCPE, and DX38BT allows local administrators with ring 0 privileges to gain additional privileges and modify code that is running in System Management Mode, or access hypervisory memory as…
ModificadaMedia (4.3)1.1%—Phpscriptsnow President Bios20/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to inject arbitrary web script or HTML via the rank parameter.
ModificadaAlta (7.5)1.2%—Phpscriptsnow President Bios20/8/200916/6/2026
SQL injection vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to execute arbitrary SQL commands via the rank parameter.
ModificadaMedia (6.5)1.9%💥 ExploitBioscripts Minitwitter22/7/200916/6/2026
index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via an opt action.
ModificadaMedia (6)0.82%💥 ExploitBioscripts Minitwitter22/7/200916/6/2026
Multiple SQL injection vulnerabilities in MiniTwitter 0.2 beta, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via the (1) user parameter to (a) index.php and (b) rss.php.
ModificadaBaja (2.1)0.36%—Intel Bios3/9/200816/6/2026
Intel firmware PE94510M.86A.0050.2007.0710.1559 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.
ModificadaMedia (4.9)0.32%—Compaq 2210 Series BiosCompaq 2510 Series BiosCompaq 2710 Series BiosCompaq 6510 Series Bios+931/3/200816/6/2026
Unspecified vulnerability in the BIOS F.04 through F.11 for the HP Compaq Business Notebook PC allows local users to cause a denial of service via unspecified vectors.
Orbitaley — Vulnerabilidades