Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2765▼ 50 respecto a la semana anterior
Críticas / altas1432▲ 200 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)95▼ 405 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.1)0.54%—ARM C1-ultraAIARM C1-premiumAIARM Neoverse V3AIARM Neoverse V3aeAI+179/6/20264/9/2026
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.
AnalizadaAlta (7.9)0.17%—ARM C1-ultra FirmwareARM C1-premium FirmwareARM Cortex-a710 FirmwareARM Cortex-x2 Firmware+714/1/202617/6/2026
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.
AnalizadaMedia (5.1)0.17%—ARM Cortex-a57 FirmwareARM Cortex-a72 FirmwareARM Cortex-a73 FirmwareARM Cortex-a75 Firmware22/1/202517/6/2026
In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may allow an adversary to gain a weak form of control over the victim's branch history.
AnalizadaCrítica (9.8)0.56%—ARM Cortex-a710 FirmwareARM Cortex-a77 FirmwareARM Cortex-a78 FirmwareARM Cortex-a78ae Firmware+1210/12/202417/6/2026
Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2…
ModificadaMedia (5.5)0.24%—ARM Cortex-a77 FirmwareXEN8/12/202317/6/2026
Cortex-A77 cores (r0p0 and r1p0) are affected by erratum 1508412 where software, under certain circumstances, could deadlock a core due to the execution of either a load to device or non-cacheable memory, and either a store exclusive or register read of the Physical Address Register (PAR_EL1) in close proximity.
ModificadaAlta (7.5)0.83%—ARM Cortex-a53 FirmwareARM Cortex-a55 FirmwareARM Cortex-a57 FirmwareARM Cortex-a72 Firmware+610/1/202317/6/2026
The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture."
ModificadaMedia (5.6)0.50%—XENARM Cortex-r7 FirmwareARM Cortex-r8 FirmwareARM Cortex-a57 Firmware+1813/3/202217/6/2026
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive…
ModificadaMedia (4.7)0.30%—Amperecomputing Ampere Altra MAX FirmwareAmperecomputing Ampere Altra FirmwareARM Neoverse-e1 FirmwareARM Neoverse-v1 Firmware+1810/3/202217/6/2026
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to…
ModificadaMedia (5.5)0.61%—XENARM Cortex-a72Broadcom Bcm2711Intel Core I7-10700k+49/6/202117/6/2026
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.
ModificadaMedia (5.5)0.33%—XENARM Cortex-a72Broadcom Bcm2711Intel Core I7-10700k+49/6/202117/6/2026
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.
ModificadaMedia (5.5)0.49%—ARM Cortex-a32 FirmwareARM Cortex-a35 FirmwareARM Cortex-a53 FirmwareARM Cortex-a57 Firmware+48/6/202017/6/2026
Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."
ModificadaAlta (7.7)5.1%—Thehive-project Cortex-analyzers9/5/201917/6/2026
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, select URL for Data Type, and provide an SSRF payload like "http://127.0.0.1:22" in the Data parameter. The result can be seen in the main…
ModificadaMedia (5.6)8.6%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+22110/7/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.
ModificadaMedia (5.6)7.5%—Intel Atom CIntel Atom EIntel Atom ZIntel Celeron J+19522/5/201817/6/2026
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
ModificadaMedia (5.5)61%—Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+27822/5/201817/6/2026
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),…
ModificadaMedia (5.6)0.67%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+20527/3/201817/6/2026
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope.
ModificadaMedia (5.6)84%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+2054/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
ModificadaMedia (5.6)94%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+3044/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaMedia (5.6)74%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+2164/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.