Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.7) | 0.16% | — | Samsung Automotive Processor Exynos Auto 8890AISamsung Automotive Processor Exynos Auto V7AISamsung Automotive Processor Exynos Auto V9AISamsung Automotive Processor Exynos Auto V920AI | 14/9/2026 | 28/9/2026 | An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel. | |
| Aplazada | Crítica (9.1) | 0.56% | — | Form Processor Field HtmlareaAIPerl Html TidyAIPerl Locale MaketextAI | 13/8/2026 | 26/8/2026 | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting… | |
| Pendiente de análisis | Media (4) | 0.11% | — | Intel ProcessorsAI | 11/8/2026 | 12/8/2026 | Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Intel ProcessorsAI | 11/8/2026 | 12/8/2026 | Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially… | |
| En análisis | Media (4.5) | 0.10% | — | Intel Xeon ProcessorAI | 11/8/2026 | 12/8/2026 | Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when… | |
| En análisis | Media (6.8) | 0.08% | — | Intel Xeon Scalable ProcessorsAI | 11/8/2026 | 12/8/2026 | Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially… | |
| Pendiente de análisis | Media (4.5) | 0.10% | — | Intel ProcessorsAI | 11/8/2026 | 29/9/2026 | Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access… | |
| Pendiente de análisis | Media (4.3) | 0.09% | — | Intel Xeon 6 Scalable ProcessorsAIIntel TDXAI | 11/8/2026 | 29/9/2026 | Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via… | |
| Pendiente de análisis | Media (4) | 0.13% | — | AMD Secure ProcessorAIAMD IommuAI | 9/6/2026 | 23/7/2026 | Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD Secure Processor (ASP), potentially resulting in loss of integrity. | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | AMD Secure ProcessorAI | 1/6/2026 | 22/7/2026 | Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures leading to a potential escalation of privileges. | |
| Pendiente de análisis | Media (4.6) | 0.11% | — | AMD Secure ProcessorAI | 15/5/2026 | 17/6/2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to cause out-of-bounds read, potentially resulting in SOC Driver memory contents exposure or an exception | |
| Pendiente de análisis | Media (5.3) | 0.21% | — | AMD Secure ProcessorAI | 15/5/2026 | 17/6/2026 | Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a function without sufficient privileges and successfully write data, potentially resulting in loss of integrity of availability. | |
| Pendiente de análisis | Alta (8.8) | 0.10% | — | AMD Secure ProcessorAI | 15/5/2026 | 17/6/2026 | Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution. | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | AMD Secure ProcessorAIAMD Video Core NextAI | 15/5/2026 | 17/6/2026 | Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure Processor (ASP) could allow an attacker with the ability to write outside the trusted memory range (TMR) to change the execution flow of the Video Core Next (VCN) firmware potentially impacting… | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Secure Processor PCI DriverAI | 15/5/2026 | 17/6/2026 | Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in a loss of platform integrity or crash. | |
| Pendiente de análisis | Media (6.9) | 0.11% | — | AMD Secure Processor PCI DriverAI | 15/5/2026 | 17/6/2026 | Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in a crash or denial of service | |
| Pendiente de análisis | Alta (8.5) | 0.13% | — | AMD Secure ProcessorAIAMD SEV SNPAI | 13/5/2026 | 17/6/2026 | Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity. | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Intel ProcessorsAI | 12/5/2026 | 17/6/2026 | Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within VMX non-root (guest) operation may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a high complexity… | |
| Aplazada | Alta (7.5) | 0.34% | — | Samsung Mobile Processor Exynos 980AISamsung Mobile Processor Exynos 990AISamsung Mobile Processor Exynos 850AISamsung Mobile Processor Exynos 2100AI+12 | 5/5/2026 | 17/6/2026 | An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, W920, W930, W1000, Modem 5123, and Modem 5300. Incorrect handling of 5G NR NAS registration accept messages leads to a Denial of Service. | |
| Pendiente de análisis | Media (5.9) | 0.11% | — | AMD Secure Processor FirmwareAIAMD ZEN 5AI | 16/4/2026 | 17/6/2026 | A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity. | |
| Pendiente de análisis | Media (5.8) | 0.11% | — | Intel Pentium Processor Silver SeriesAIIntel Celeron Processor J SeriesAIIntel Celeron Processor N SeriesAI | 8/4/2026 | 25/7/2026 | Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high complexity attack… | |
| Aplazada | Alta (8.4) | 0.14% | — | AMD Secure ProcessorAI | 12/2/2026 | 17/6/2026 | Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety violation potentially resulting in loss of confidentiality, integrity, or availability. | |
| Aplazada | Alta (8.7) | 0.15% | — | AMD Secure ProcessorAI | 11/2/2026 | 17/6/2026 | Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to functions in the trusted execution environment resulting in arbitrary code execution | |
| Aplazada | Media (5.4) | 0.13% | — | AMD Secure ProcessorAI | 10/2/2026 | 17/6/2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwrite the memory, potentially resulting in arbitrary code execution. | |
| Aplazada | Alta (7.3) | 0.14% | — | AMD Secure ProcessorAI | 10/2/2026 | 17/6/2026 | A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially resulting in privilege escalation and arbitrary code execution. |