Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2617▼ 302 respecto a la semana anterior
Críticas / altas1346▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

96 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.8)0.15%—Nvidia ConnectxAINvidia BluefieldAI29/9/202629/9/2026
NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.
AplazadaCrítica (9.8)0.80%—Intel Uefi FirmwareAI14/9/202630/9/2026
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT = 9 and can obtain 511 entries for the 510-element Sd->mCLen heap array because…
AplazadaCrítica (9.8)0.80%—Intel Uefi FirmwareAI14/9/202630/9/2026
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-length values read from a crafted Tiano or EFI compressed firmware bitstream remain within the…
Pendiente de análisisAlta (8.2)0.18%—Uefi BiosAI9/9/202610/9/2026
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
En análisisMedia (6.7)0.11%—IBM UefiAI3/9/20263/9/2026
Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure.
AnalizadaAlta (8.2)0.20%—Nvidia DGX Spark Uefi25/8/20269/9/2026
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
AnalizadaMedia (6)0.18%—Nvidia DGX Spark Uefi25/8/20269/9/2026
NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.
AnalizadaAlta (8.2)0.15%—Nvidia DGX Spark Uefi25/8/20269/9/2026
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
AnalizadaAlta (8.2)0.15%—Nvidia DGX Spark Uefi25/8/20269/9/2026
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
AnalizadaMedia (6)0.13%—Nvidia DGX Spark Uefi25/8/20269/9/2026
NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure.
Pendiente de análisisAlta (8.2)0.37%—IBM UefiAI12/8/202631/8/2026
In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
Pendiente de análisisMedia (4)0.12%—Intel Uefi FirmwareAI11/8/202612/8/2026
Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements…
Pendiente de análisisCrítica (9)0.37%—Nvidia ConnectxAINvidia BluefieldAI1/7/202630/9/2026
NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
Pendiente de análisisCrítica (9)0.37%—Nvidia ConnectxAINvidia BluefieldAI1/7/202630/9/2026
NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
AplazadaAlta (7.8)0.11%—Microsoft Uefi Shim BootloaderAI9/6/202623/7/2026
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads.…
Pendiente de análisisMedia (5.6)0.10%—Intel Uefi FirmwareAI12/5/202617/6/2026
Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack…
Pendiente de análisisMedia (5.6)0.08%—Intel Uefi Pdasmm ModuleAI10/3/202617/6/2026
Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack…
Pendiente de análisisMedia (5.6)0.10%—Intel Uefi PdasmmAI10/3/202617/6/2026
Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack…
Pendiente de análisisAlta (8.7)0.13%—Intel Uefi FirmwareAI10/3/202617/6/2026
Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack…
Pendiente de análisisMedia (5.9)0.14%—Intel Uefi FirmwareAI10/3/202617/6/2026
Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are…
Pendiente de análisisBaja (1.8)0.10%—Intel Uefi DXEAI10/3/202617/6/2026
Improper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack…
Pendiente de análisisAlta (7.1)0.10%—Intel Uefi ImcerrorhandlerAI10/3/202617/6/2026
Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when…
Pendiente de análisisAlta (8.7)0.11%—Intel Uefi FlashucacmsmmAI10/3/202617/6/2026
Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may potentially occur via local access when attack…
Pendiente de análisisAlta (7.1)0.10%—Intel Uefi Wheaerst ModuleAI10/3/202617/6/2026
Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack…
Pendiente de análisisMedia (5.7)0.10%—Intel Uefi FirmwareAI10/3/202617/6/2026
Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable data manipulation. This result may potentially occur via local access when attack…