Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. | |
| Modificada | Media (6.5) | 1.9% | — | Google ChromeOpensuse Backports SLE | 11/2/2020 | 17/6/2026 | Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. | |
| Modificada | Media (6.5) | 2.0% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.0% | — | Google ChromeOpensuse Backports SLE | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.8% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | |
| Modificada | Media (6.5) | 1.9% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.7% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Media (5.4) | 1.7% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.9% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.5% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. | |
| Modificada | Media (4.3) | 1.3% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page. | |
| Modificada | Alta (8.8) | 3.1% | — | Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+4 | 11/2/2020 | 17/6/2026 | Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+4 | 11/2/2020 | 17/6/2026 | Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.2% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (5) | 1.3% | — | Nextcloud ServerOpensuse Backports SLENovell Suse Linux Enterprise Server | 4/2/2020 | 17/6/2026 | An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application. | |
| Modificada | Media (4.9) | 1.5% | — | Nextcloud ServerOpensuse BackportsSuse Linux Enterprise Server | 4/2/2020 | 17/6/2026 | Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders. | |
| Modificada | Media (5.3) | 1.9% | — | Nextcloud ServerOpensuse Backports SLESuse Package HUB | 4/2/2020 | 17/6/2026 | Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled. | |
| Modificada | Alta (8) | 1.1% | — | Nextcloud ServerOpensuse Backports | 4/2/2020 | 17/6/2026 | A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes. | |
| Modificada | Alta (7.8) | 0.36% | — | Suse MailmanOpensuse Backports SLE | 24/1/2020 | 17/6/2026 | A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1 allowed local attackers to escalate their privileges from user wwwrun to root. Additionally arbitrary files could be changed to group mailman. This issue affects: SUSE… | |
| Modificada | Alta (7.8) | 0.50% | — | Suse INNOpensuse Backports SLEOpensuse Leap | 24/1/2020 | 17/6/2026 | The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn version 2.4.2-170.21.3.1 and prior versions. openSUSE Factory inn version 2.6.2-2.2 and prior… | |
| Modificada | Media (5.5) | 0.26% | — | Apt-cacher-ng Project Apt-cacher-ngOpensuse Backports | 23/1/2020 | 17/6/2026 | The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1. | |
| Modificada | Alta (8.1) | 2.9% | — | StorebackupDebian LinuxOpensuse Backports SLEOpensuse Leap+1 | 21/1/2020 | 17/6/2026 | storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.) | |
| Modificada | Media (5.5) | 0.47% | — | Apt-cacher-ng Project Apt-cacher-ngDebian LinuxOpensuse BackportsOpensuse Leap | 21/1/2020 | 17/6/2026 | apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed.… | |
| Modificada | Alta (7) | 0.25% | — | Squid Analysis Report Generator Project Squid Analysis Report GeneratorOpensuse Backports SLEOpensuse Leap | 21/1/2020 | 17/6/2026 | log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create the directory, and place symlinks in it… |