Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.64% | — | Supermicro X14dbg-dapAISupermicro X14dbiAI | 22/7/2026 | 23/7/2026 | Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC. | |
| Pendiente de análisis | Alta (7.2) | 0.66% | — | Supermicro BMCAISupermicro As-2115hs-tnrAI | 4/6/2026 | 22/7/2026 | There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. An attacker may obtain administrator privileges and inject specially crafted characters into the SMTP service configuration. This may cause the underlying system to execute unintended commands during process invocation. Potential… | |
| Aplazada | Alta (8.4) | 0.13% | — | Supermicro Mbd-x13sem-fAI | 16/1/2026 | 17/6/2026 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image. | |
| Aplazada | Alta (7.2) | 0.31% | — | Supermicro Bmd-x12stw-fAI | 16/1/2026 | 17/6/2026 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can update the system firmware with a specially crafted image. | |
| Aplazada | Alta (7.2) | 0.34% | — | Supermicro Mbd-x13sedw-fAI | 18/11/2025 | 17/6/2026 | There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web server, an attacker can use a specially crafted payload to trigger the Stack buffer overflow vulnerability. | |
| Aplazada | Media (5.5) | 0.32% | — | Supermicro BMCAI | 18/11/2025 | 17/6/2026 | Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access to the BMC exploit stack buffer via a crafted header and achieve arbitrary code execution of the BMC’s firmware operating system. | |
| Aplazada | Alta (7.2) | 0.34% | — | Supermicro Mbd-x13sedw-fAI | 18/11/2025 | 17/6/2026 | There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web server, an attacker can use a specially crafted payload to trigger the Stack buffer overflow vulnerability. | |
| Aplazada | Media (5.4) | 0.23% | — | Supermicro BMCAIInsyde SmashAI | 13/11/2025 | 17/6/2026 | Supermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability | |
| Aplazada | Alta (7.2) | 0.31% | — | Supermicro Mbd-x12stwAISupermicro BMC FirmwareAI | 19/9/2025 | 17/6/2026 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a specially crafted image. | |
| Aplazada | Alta (7.2) | 0.31% | — | Supermicro Mbd-x13sem-fAI | 19/9/2025 | 17/6/2026 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image. | |
| Aplazada | Alta (7.2) | 0.53% | — | Supermicro Mbd-x12dpg-oa6AI | 4/2/2025 | 17/6/2026 | A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with administrator privileges can upload a specially crafted image, which can cause a stack overflow due to the unchecked fat->fsd.max_fld. | |
| Aplazada | Alta (7.2) | 0.53% | — | Supermicro Mbd-x12dpg-oa6AI | 4/2/2025 | 17/6/2026 | A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can upload a specially crafted image that will cause a stack overflow is caused by not checking fld->used_bytes. | |
| Aplazada | Alta (7.2) | 0.25% | — | Supermicro Mbd-x12dpg-oa6AI | 4/2/2025 | 17/6/2026 | There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection and bypass the signature verification process | |
| Aplazada | Alta (7.5) | 0.15% | — | Supermicro X11dph-tAISupermicro X11dph-tqAISupermicro X11dph-iAI | 15/7/2024 | 17/6/2026 | An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4. | |
| Aplazada | Alta (7.5) | 0.15% | — | Supermicro X11dph-tAISupermicro X11dph-tqAISupermicro X11dph-iAI | 15/7/2024 | 17/6/2026 | An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4. | |
| Aplazada | Alta (7.5) | 0.15% | — | Supermicro X11dpg-hgx2AISupermicro X11pdg-qtAISupermicro X11pdg-otAISupermicro X11pdg-snAI | 15/7/2024 | 17/6/2026 | An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN motherboards with BIOS firmware before 4.4. | |
| Aplazada | Crítica (9.8) | 1.3% | — | Supermicro BMC FirmwareAISupermicro X11AISupermicro X12AISupermicro H12AI+5 | 11/7/2024 | 17/6/2026 | An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user can post crafted data to the interface that triggers a stack buffer overflow, and may lead to arbitrary remote code execution on a BMC. | |
| Aplazada | Alta (7.5) | 0.53% | — | Supermicro SMMAISupermicro Smm2AISupermicro FPCAI | 15/4/2024 | 17/6/2026 | An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information. | |
| Analizada | Alta (8.3) | 0.66% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on Windows. | |
| Analizada | Alta (7.2) | 18% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges. | |
| Analizada | Alta (8.3) | 0.56% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Alta (8.3) | 0.56% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Alta (8.3) | 0.57% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Media (6.5) | 0.57% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Alta (8.3) | 0.78% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. |