Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2617▼ 302 respecto a la semana anterior
Críticas / altas1346▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.8) | 0.15% | — | Nvidia ConnectxAINvidia BluefieldAI | 29/9/2026 | 29/9/2026 | NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Crítica (9.8) | 0.80% | — | Intel Uefi FirmwareAI | 14/9/2026 | 30/9/2026 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT = 9 and can obtain 511 entries for the 510-element Sd->mCLen heap array because… | |
| Aplazada | Crítica (9.8) | 0.80% | — | Intel Uefi FirmwareAI | 14/9/2026 | 30/9/2026 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-length values read from a crafted Tiano or EFI compressed firmware bitstream remain within the… | |
| Pendiente de análisis | Alta (8.2) | 0.18% | — | Uefi BiosAI | 9/9/2026 | 10/9/2026 | UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts. | |
| En análisis | Media (6.7) | 0.11% | — | IBM UefiAI | 3/9/2026 | 3/9/2026 | Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure. | |
| Analizada | Alta (8.2) | 0.20% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. | |
| Analizada | Media (6) | 0.18% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi. | |
| Analizada | Alta (8.2) | 0.15% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. | |
| Analizada | Alta (8.2) | 0.15% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. | |
| Analizada | Media (6) | 0.13% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure. | |
| Pendiente de análisis | Alta (8.2) | 0.37% | — | IBM UefiAI | 12/8/2026 | 31/8/2026 | In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution. | |
| Pendiente de análisis | Media (4) | 0.12% | — | Intel Uefi FirmwareAI | 11/8/2026 | 12/8/2026 | Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements… | |
| Pendiente de análisis | Crítica (9) | 0.37% | — | Nvidia ConnectxAINvidia BluefieldAI | 1/7/2026 | 30/9/2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. | |
| Pendiente de análisis | Crítica (9) | 0.37% | — | Nvidia ConnectxAINvidia BluefieldAI | 1/7/2026 | 30/9/2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. | |
| Aplazada | Alta (7.8) | 0.11% | — | Microsoft Uefi Shim BootloaderAI | 9/6/2026 | 23/7/2026 | Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads.… | |
| Pendiente de análisis | Media (5.6) | 0.10% | — | Intel Uefi FirmwareAI | 12/5/2026 | 17/6/2026 | Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Media (5.6) | 0.08% | — | Intel Uefi Pdasmm ModuleAI | 10/3/2026 | 17/6/2026 | Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Media (5.6) | 0.10% | — | Intel Uefi PdasmmAI | 10/3/2026 | 17/6/2026 | Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Alta (8.7) | 0.13% | — | Intel Uefi FirmwareAI | 10/3/2026 | 17/6/2026 | Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Media (5.9) | 0.14% | — | Intel Uefi FirmwareAI | 10/3/2026 | 17/6/2026 | Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are… | |
| Pendiente de análisis | Baja (1.8) | 0.10% | — | Intel Uefi DXEAI | 10/3/2026 | 17/6/2026 | Improper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | Intel Uefi ImcerrorhandlerAI | 10/3/2026 | 17/6/2026 | Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when… | |
| Pendiente de análisis | Alta (8.7) | 0.11% | — | Intel Uefi FlashucacmsmmAI | 10/3/2026 | 17/6/2026 | Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | Intel Uefi Wheaerst ModuleAI | 10/3/2026 | 17/6/2026 | Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Media (5.7) | 0.10% | — | Intel Uefi FirmwareAI | 10/3/2026 | 17/6/2026 | Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable data manipulation. This result may potentially occur via local access when attack… |