Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.84% | — | Script Mobile Browser Color Select | 13/6/2022 | 17/6/2026 | The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the admin_update_data() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via… | |
| Modificada | Media (6.5) | 0.70% | — | Ucweb UC Browser | 13/6/2022 | 17/6/2026 | A vulnerability was found in Ucweb UC Browser 11.2.5.932. It has been classified as critical. Affected is an unknown function of the component HTML Handler. The manipulation of the argument title leads to improper restriction of rendered ui layers (URL). It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Alta (7.5) | 0.44% | — | MI Browser | 21/4/2022 | 17/6/2026 | An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not verify the validity of the incoming data. Attackers can perform sensitive operations by exploiting this. | |
| Modificada | Alta (8.8) | 0.63% | — | Sermon Browser Project Sermon Browser | 28/3/2022 | 17/6/2026 | The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones. | |
| Modificada | Baja (2.5) | 0.27% | — | Mirmay File ManagerMirmay Secure Private Browser | 28/3/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5. Affected is the Auto Lock. A race condition leads to a local authentication bypass. The exploit has been disclosed to the public and may be used. | |
| Modificada | Baja (3.7) | 0.98% | — | DAJ I-filter Browser & Cloud MultiagentDAJ I-filter | 10/3/2022 | 17/6/2026 | Improper check for certificate revocation in i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9.50R10 and earlier, i-FILTER Browser & Cloud MultiAgent for Windows Ver.4.93R04 and earlier, and D-SPA (Ver.3 / Ver.4) using i-FILTER allows a remote unauthenticated attacker to conduct a man-in-the-middle attack and… | |
| Modificada | Alta (8.8) | 6.7% | 💥 Exploit | Filebrowser | 4/2/2022 | 17/6/2026 | A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. An admin can run commands using the FileBrowser and hence it leads to RCE. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (8.8) | 0.78% | — | Browser AND Operating System Finder Project Browser AND Operating System Finder | 1/12/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of an administrator via unspecified vectors. | |
| Modificada | Alta (7.8) | 3.9% | — | Checkpoint Harmony BrowseCheckpoint Sandblast Agent FOR Browsers | 22/10/2021 | 17/6/2026 | The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an attacker running an installer before 90.08.7405 can start the installation repair and place a… | |
| Modificada | Alta (8.8) | 1.5% | — | Qutebrowser | 21/10/2021 | 17/6/2026 | qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially crafted `qutebrowserurl:...` URL can lead to execution of qutebrowser commands,… | |
| Modificada | Media (6.1) | 0.47% | — | Torproject TOR Browser | 24/9/2021 | 17/6/2026 | Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an attacker might be able to compare them to timestamp data collected by the destination server (or… | |
| Modificada | Crítica (9.3) | 0.84% | — | Jscom Revoworks Browser | 17/9/2021 | 17/6/2026 | Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restriction and to exchange unauthorized files between the local environment and the isolated environment or settings of the web browser via unspecified vectors. | |
| Modificada | Crítica (9.6) | 1.3% | — | Jscom Revoworks Browser | 17/9/2021 | 17/6/2026 | Improper control of program execution vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to execute an arbitrary command or code via unspecified vectors. | |
| Modificada | Media (5.3) | 1.3% | — | Yandex Browser | 13/9/2021 | 17/6/2026 | Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar | |
| Modificada | Alta (7.3) | 0.53% | — | Yandex Browser | 13/9/2021 | 17/6/2026 | Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing | |
| Modificada | Media (5.4) | 0.78% | — | Filebrowser Project Filebrowser | 31/8/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user authorized to upload a malicious .svg file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger malicious OS commands on the server running the… | |
| Modificada | Alta (7.8) | 0.41% | — | Yandex Browser | 17/8/2021 | 17/6/2026 | Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process. | |
| Modificada | Media (5.4) | 0.62% | — | Prothemedesign Browser Screenshots | 12/7/2021 | 17/6/2026 | The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks as the image_class parameter of the browser-shot shortcode was not escaped. | |
| Modificada | Media (6.5) | 1.2% | — | Brave Browser | 12/7/2021 | 17/6/2026 | Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowing through Tor if adblocking was enabled. | |
| Modificada | Media (6.1) | 0.81% | — | Cisco Virtualized Voice Browser | 8/7/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Virtualized Voice Browser could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate… | |
| Modificada | Media (5.3) | 2.4% | — | Browserslist Project Browserslist | 28/4/2021 | 17/6/2026 | The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries. | |
| Modificada | Media (6.1) | 0.74% | — | Cheetah Browser Project Cheetah Browser | 13/4/2021 | 17/6/2026 | A UXSS was discovered in the Thanos-Soft Cheetah Browser in Android 1.2.0 due to the inadequate filter of the intent scheme. This resulted in Cross-site scripting on the cheetah browser in any website. | |
| Modificada | Crítica (10) | 4.8% | — | Browserup Proxy | 24/12/2020 | 17/6/2026 | BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Proxy works well as a standalone proxy server, but it is especially useful when embedded in Selenium tests. A Server-Side Template Injection was identified in BrowserUp Proxy… | |
| Modificada | Media (5.3) | 1.0% | — | Spatie Browsershot | 11/12/2020 | 17/6/2026 | This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF. |