Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.8) | 0.11% | — | AMD Power Management FirmwareAI | 15/5/2026 | 17/6/2026 | Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when exporting table data from SMU to DRAM potentially resulting in a loss of confidentiality and/or availability. | |
| Aplazada | Alta (7.2) | 0.10% | — | AMD Power Management FirmwareAI | 12/2/2026 | 17/6/2026 | An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution. | |
| Aplazada | Media (6.8) | 0.12% | — | Lenovo Power Management DriverAI | 15/10/2025 | 17/6/2026 | A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a local authenticated user to cause a Windows blue screen error. | |
| Aplazada | Media (6) | 0.13% | — | AMD Power Management FirmwareAI | 6/9/2025 | 17/6/2026 | Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to send arbitrary input data potentially causing a GPU Reset condition. | |
| Aplazada | Media (4.4) | 0.14% | — | AMD Power Management FirmwareAIAMD AgesaAI | 6/9/2025 | 17/6/2026 | Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity. | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (5.4) | 0.30% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (5.3) | 0.41% | — | Cisco Firepower Management CenterCisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this… | |
| Analizada | Media (5.4) | 0.31% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit… | |
| Analizada | Media (6.1) | 0.39% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (6.5) | 0.62% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability exists because the web-based… | |
| Analizada | Media (6.1) | 0.41% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Aplazada | Media (5) | 0.14% | — | AMD Power Management FirmwareAI | 13/8/2024 | 17/6/2026 | Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability. | |
| Aplazada | Baja (1.9) | 0.14% | — | Pmfw Power Management FirmwareAI | 13/8/2024 | 17/6/2026 | Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially resulting in information disclosure. | |
| Modificada | Media (4.4) | 0.17% | — | Intel Power Management Controller | 9/2/2022 | 17/6/2026 | Improper locking in the Power Management Controller (PMC) for some Intel Chipset firmware before versions pmc_fw_lbg_c1-21ww02a and pmc_fw_lbg_b0-21ww02a may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to a lack of proper error handling when an… | |
| Modificada | Media (6.1) | 0.61% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (4.8) | 0.48% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.1) | 2.0% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The vulnerability is due to insufficient input… | |
| Modificada | Media (6) | 0.21% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user… | |
| Modificada | Alta (7.8) | 0.27% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (7.8) | 0.27% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.6) | 1.7% | — | Cisco Ironport WEB Security ApplianceCisco Secure Firewall Management CenterCisco Firepower Management Center Virtual Appliance Firmware | 18/8/2021 | 17/6/2026 | A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised… |