Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 67% | — | OpensslNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Ontap 9+15 | 3/9/2024 | 17/6/2026 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service.… | |
| Modificada | Alta (8.1) | 100% | — | Sonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+49 | 1/7/2024 | 1/9/2026 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | |
| Modificada | Media (6) | 0.16% | — | AMD Ryzen 7 5700g FirmwareAMD Ryzen 7 5700ge FirmwareAMD Ryzen 5 5600g FirmwareAMD Ryzen 5 5600gt Firmware+125 | 13/2/2024 | 2/9/2026 | Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability. | |
| Analizada | Alta (7.8) | 28% | ⚠ Explotación activa | Netapp H300s FirmwareNetapp H500s FirmwareNetapp H700s FirmwareNetapp H410s Firmware+14 | 31/1/2024 | 7/8/2026 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when… | |
| Modificada | Media (6.5) | 1.2% | — | Khronos OpenclKhronos VulkanImaginationtech DDKAMD Instinct Mi300x Firmware+128 | 16/1/2024 | 17/6/2026 | A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures. | |
| Modificada | Alta (8) | 0.40% | — | Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+625 | 14/11/2023 | 17/6/2026 | Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Baja (3.5) | 0.30% | — | Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+625 | 14/11/2023 | 17/6/2026 | Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Crítica (9.8) | 1.0% | — | AMD Ryzen 7 5700g FirmwareAMD Ryzen 7 5700ge FirmwareAMD Ryzen 5 5600g FirmwareAMD Ryzen 5 5600ge Firmware+60 | 14/11/2023 | 17/6/2026 | Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution. | |
| Modificada | Alta (8.1) | 0.45% | — | AMD Ryzen 3 5100 FirmwareAMD Ryzen 3 5300g FirmwareAMD Ryzen 3 5300ge FirmwareAMD Ryzen 5 5500 Firmware+67 | 14/11/2023 | 17/6/2026 | A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation. | |
| Modificada | Alta (7.8) | 0.21% | — | AMD Ryzen 3 5100 FirmwareAMD Ryzen 3 5300g FirmwareAMD Ryzen 3 5300ge FirmwareAMD Ryzen 5 5500 Firmware+67 | 14/11/2023 | 17/6/2026 | Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | AMD Ryzen 3 5100 FirmwareAMD Ryzen 3 5300g FirmwareAMD Ryzen 3 5300ge FirmwareAMD Ryzen 5 5500 Firmware+67 | 14/11/2023 | 17/6/2026 | Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8) | 0.35% | — | Intel Celeron J6413 FirmwareIntel Celeron N6211 FirmwareIntel Pentium J6425 FirmwareIntel Pentium N6415 Firmware+294 | 11/8/2023 | 17/6/2026 | Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Media (4.4) | 0.17% | — | Intel Pentium J6426 FirmwareIntel Pentium J4205 FirmwareIntel Pentium J3710 FirmwareIntel Pentium J2900 Firmware+902 | 11/8/2023 | 17/6/2026 | Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (6.5) | 3.0% | — | Redhat Enterprise LinuxXENIntel MicrocodeIntel Xeon E-2314 Firmware+530 | 11/8/2023 | 17/6/2026 | Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.7) | 7.3% | — | Fedoraproject FedoraDebian LinuxAMD Ryzen 9 5950x FirmwareAMD Ryzen 9 5900x Firmware+151 | 8/8/2023 | 17/6/2026 | A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. | |
| Modificada | Alta (7.8) | 0.32% | — | AMD Ryzen 3 3300 FirmwareAMD Ryzen 3 3300x FirmwareAMD Ryzen 5 3600 FirmwareAMD Ryzen 5 3600x Firmware+115 | 8/8/2023 | 17/6/2026 | Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Xeon E-2314 FirmwareIntel Xeon E-2324g FirmwareIntel Xeon E-2334 FirmwareIntel Xeon E-2336 Firmware+463 | 10/5/2023 | 17/6/2026 | Exposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.25% | — | Intel Xeon E-2314 FirmwareIntel Xeon E-2324g FirmwareIntel Xeon E-2334 FirmwareIntel Xeon E-2336 Firmware+269 | 10/5/2023 | 17/6/2026 | Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.25% | — | Intel Xeon Gold 5315y FirmwareIntel Xeon Gold 5317 FirmwareIntel Xeon Gold 5318n FirmwareIntel Xeon Gold 5318s Firmware+223 | 16/2/2023 | 17/6/2026 | Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.5) | 90% | — | Openbsd OpensshFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp A250 Firmware+2 | 3/2/2023 | 17/6/2026 | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states… | |
| Modificada | Media (6.5) | 0.42% | — | Intel Killer Wifi SoftwareIntel Proset/wireless WifiIntel Uefi Wifi DriverIntel Killer Wi-fi 6 Ax1650 Firmware+338 | 11/11/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.26% | — | Intel Xeon Gold 5315y FirmwareIntel Xeon Gold 5317 FirmwareIntel Xeon Gold 5318n FirmwareIntel Xeon Gold 5318s Firmware+68 | 18/8/2022 | 17/6/2026 | Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.32% | — | Linux KernelDebian LinuxNetapp A700s FirmwareNetapp Active IQ Unified Manager+20 | 27/7/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice. | |
| Modificada | Media (5.5) | 0.36% | — | Intel Celeron N6210 FirmwareIntel Celeron N4500 FirmwareIntel Celeron N4505 FirmwareIntel Celeron N5100 Firmware+395 | 12/5/2022 | 17/6/2026 | Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.7) | 0.26% | — | Intel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r FirmwareIntel Xeon Gold 5220r FirmwareIntel Xeon Gold 6208u Firmware+669 | 12/5/2022 | 17/6/2026 | Out-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access. |