Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2011 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 13% | 💥 PoC | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. | |
| Modificada | Alta (7.8) | 0.34% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events. | |
| Modificada | Media (4.3) | 2.6% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.0% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome Extension. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file. | |
| Modificada | Media (6.5) | 1.8% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | |
| Modificada | Alta (8.8) | 3.3% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 19/2/2019 | 17/6/2026 | An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code via a crafted HTML page. | |
| Modificada | Alta (8.8) | 3.0% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.2% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension. | |
| Modificada | Media (6.5) | 1.3% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK. | |
| Modificada | Media (6.5) | 1.6% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (5.5) | 0.54% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent. | |
| Modificada | Alta (8.8) | 1.4% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect pointer management in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 19/2/2019 | 17/6/2026 | Incorrect object lifecycle management in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | Insufficient checks of pointer validity in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Crítica (9.6) | 1.5% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect object lifecycle management in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |