Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.13% | — | AMD AgesaAI | 2/9/2026 | 4/9/2026 | Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. | |
| Pendiente de análisis | Media (6.9) | 0.09% | — | AMD AgesaAIAMD Ddr5AI | 15/5/2026 | 17/6/2026 | Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse the unprotected PMIC interface to create a permanent denial of service condition or affect the integrity of the memory module. | |
| Aplazada | Media (4.4) | 0.14% | — | AMD Power Management FirmwareAIAMD AgesaAI | 6/9/2025 | 17/6/2026 | Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity. | |
| Modificada | Media (4.3) | 1.6% | — | Garagesale Project Garagesale | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in templates/printAdminUsersList_Footer.tpl.php in the GarageSale plugin before 1.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Garagesalesjunkie Garagesales Script | 14/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.0% | — | Garagesalesjunkie Garagesales Script | 14/8/2009 | 16/6/2026 | SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL commands via the key parameter. |