Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.8)0.11%—AMD Power Management FirmwareAI15/5/202617/6/2026
Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when exporting table data from SMU to DRAM potentially resulting in a loss of confidentiality and/or availability.
AplazadaAlta (7.2)0.10%—AMD Power Management FirmwareAI12/2/202617/6/2026
An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution.
AplazadaMedia (6.8)0.12%—Lenovo Power Management DriverAI15/10/202517/6/2026
A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a local authenticated user to cause a Windows blue screen error.
AplazadaMedia (6)0.13%—AMD Power Management FirmwareAI6/9/202517/6/2026
Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to send arbitrary input data potentially causing a GPU Reset condition.
AplazadaMedia (4.4)0.14%—AMD Power Management FirmwareAIAMD AgesaAI6/9/202517/6/2026
Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity.
AnalizadaMedia (6.1)0.32%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaMedia (6.1)0.32%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaMedia (6.1)0.32%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaMedia (5.4)0.30%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaMedia (5.3)0.41%—Cisco Firepower Management CenterCisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this…
AnalizadaMedia (5.4)0.31%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit…
AnalizadaMedia (6.1)0.39%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaMedia (6.5)0.62%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability exists because the web-based…
AnalizadaMedia (6.1)0.41%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AplazadaMedia (5)0.14%—AMD Power Management FirmwareAI13/8/202417/6/2026
Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.
AplazadaBaja (1.9)0.14%—Pmfw Power Management FirmwareAI13/8/202417/6/2026
Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially resulting in information disclosure.
ModificadaMedia (4.4)0.17%—Intel Power Management Controller9/2/202217/6/2026
Improper locking in the Power Management Controller (PMC) for some Intel Chipset firmware before versions pmc_fw_lbg_c1-21ww02a and pmc_fw_lbg_b0-21ww02a may allow a privileged user to potentially enable denial of service via local access.
ModificadaAlta (7.5)1.4%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to a lack of proper error handling when an…
ModificadaMedia (6.1)0.61%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaMedia (4.8)0.48%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (8.1)2.0%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The vulnerability is due to insufficient input…
ModificadaMedia (6)0.21%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user…
ModificadaAlta (7.8)0.27%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (7.8)0.27%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (8.6)1.7%—Cisco Ironport WEB Security ApplianceCisco Secure Firewall Management CenterCisco Firepower Management Center Virtual Appliance Firmware18/8/202117/6/2026
A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised…