Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.6) | 0.10% | — | Intel Converged Security AND Management Engine FirmwareAI | 10/2/2026 | 17/6/2026 | Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially… | |
| Aplazada | Media (6.8) | 0.10% | — | Intel Converged Security AND Management EngineAI | 12/8/2025 | 17/6/2026 | Time-of-check time-of-use race condition in firmware for some Intel(R) Converged Security and Management Engine may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.4) | 0.28% | — | Intel Converged Security AND Management EngineIntel Server Platform Services | 12/11/2020 | 17/6/2026 | Race condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01.04.400 and E3_05.01.04.200 may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Alta (7.8) | 0.36% | — | Intel Converged Security AND Management EngineIntel Server Platform ServicesIntel Trusted Execution EngineSiemens Simatic S7-1518-4 Pn/dp MFP Firmware+2 | 12/11/2020 | 17/6/2026 | Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.39% | — | Intel Converged Security AND Management Engine | 17/5/2019 | 17/6/2026 | Insufficient data sanitization vulnerability in HECI subsystem for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.52% | — | Intel Converged Security AND Management EngineIntel Trusted Execution Technology | 17/5/2019 | 17/6/2026 | Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.1) | 0.36% | — | Intel Converged Security AND Management EngineIntel Server Platform Services | 17/5/2019 | 17/6/2026 | Insufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platform Services 3.x, 4.x, Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access. |