Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.80% | — | Intel Uefi FirmwareAI | 14/9/2026 | 30/9/2026 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT = 9 and can obtain 511 entries for the 510-element Sd->mCLen heap array because… | |
| Aplazada | Crítica (9.8) | 0.80% | — | Intel Uefi FirmwareAI | 14/9/2026 | 30/9/2026 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-length values read from a crafted Tiano or EFI compressed firmware bitstream remain within the… | |
| Pendiente de análisis | Media (4) | 0.12% | — | Intel Uefi FirmwareAI | 11/8/2026 | 12/8/2026 | Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements… | |
| Pendiente de análisis | Media (5.6) | 0.10% | — | Intel Uefi FirmwareAI | 12/5/2026 | 17/6/2026 | Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Alta (8.7) | 0.13% | — | Intel Uefi FirmwareAI | 10/3/2026 | 17/6/2026 | Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Media (5.9) | 0.14% | — | Intel Uefi FirmwareAI | 10/3/2026 | 17/6/2026 | Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are… | |
| Pendiente de análisis | Media (5.7) | 0.10% | — | Intel Uefi FirmwareAI | 10/3/2026 | 17/6/2026 | Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable data manipulation. This result may potentially occur via local access when attack… | |
| Aplazada | Alta (7.6) | 0.26% | — | Intel Uefi FirmwareAI | 14/10/2025 | 17/6/2026 | Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the… | |
| Aplazada | Alta (8.2) | 0.43% | — | Microsoft Uefi FirmwareAI | 10/6/2025 | 17/6/2026 | An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security… | |
| Aplazada | Alta (8.7) | 0.16% | — | Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI | 13/5/2025 | 17/6/2026 | Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.6) | 0.15% | — | Intel Uefi Firmware D50dnpAIIntel Uefi Firmware M50fcpAI | 13/5/2025 | 17/6/2026 | Improper initialization in the UEFI firmware for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (8.7) | 0.16% | — | Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI | 13/5/2025 | 17/6/2026 | Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.11% | — | Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI | 13/5/2025 | 17/6/2026 | Time-of-check time-of-use race condition in the UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to enable escalation of privilege via local access. | |
| Aplazada | Media (5.6) | 0.16% | — | Intel Server D50dnp Uefi FirmwareAIIntel M50fcp Uefi FirmwareAI | 13/5/2025 | 17/6/2026 | Improper input validation in the UEFI firmware GenerationSetup module for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Media (6.8) | 0.22% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (6.8) | 0.23% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (8.7) | 0.19% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.25% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.25% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.8) | 0.25% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (8.7) | 0.25% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.8) | 0.20% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (8.7) | 0.28% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.25% | — | Intel Uefi FirmwareAI | 12/2/2025 | 17/6/2026 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.6) | 0.15% | — | Intel Server M20ntp Family Uefi FirmwareAI | 13/11/2024 | 17/6/2026 | Improper access control in UEFI firmware in some Intel(R) Server M20NTP Family may allow a privileged user to potentially enable information disclosure via local access. |