Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.62%—Amperecomputing Ampere Altra FirmwareAmperecomputing Ampere Altra MAX Firmware15/2/202317/6/2026
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.
ModificadaMedia (6.5)0.70%—Amperecomputing Ampere Altra MAX FirmwareAmperecomputing Ampere Altra FirmwareAmperecomputing Ampereone Firmware29/9/202217/6/2026
Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with data being processed on the system.
ModificadaAlta (7.8)0.22%—Amperecomputing Ampere Altra FirmwareAmperecomputing Ampere Altra MAX Firmware17/8/202217/6/2026
Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.
ModificadaAlta (7.5)0.72%—Amperecomputing Ampere Altra FirmwareAmperecomputing Ampere Altra MAX Firmware17/8/202217/6/2026
Ampere Altra before SRP 1.08b and Altra Max​ before SRP 2.05 allow information disclosure of power telemetry via HWmon.
ModificadaCrítica (9.8)1.3%—Amperecomputing Ampere Altra FirmwareAmperecomputing Ampere Altra MAX Firmware1/7/202217/6/2026
On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component.
ModificadaMedia (4.7)0.30%—Amperecomputing Ampere Altra MAX FirmwareAmperecomputing Ampere Altra FirmwareARM Neoverse-e1 FirmwareARM Neoverse-v1 Firmware+1810/3/202217/6/2026
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to…
Orbitaley — Vulnerabilidades