Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

326 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.5%—Google ChromeDebian LinuxSuse Package HUBOpensuse Backports SLE+410/12/201917/6/2026
Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (8.8)3.9%—Google ChromeFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+1110/12/201917/6/2026
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (7.8)0.76%—Shadowsocks-libevOpensuse Backports SLEOpensuse Leap3/12/201917/6/2026
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.
ModificadaMedia (6.5)1.7%—Redhat AnsibleOpensuse Backports SLEOpensuse LeapRedhat Openstack26/11/201917/6/2026
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
ModificadaMedia (4.3)1.2%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
ModificadaMedia (4.3)0.88%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
ModificadaMedia (4.3)1.0%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
ModificadaMedia (4.3)0.93%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (4.3)0.85%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
ModificadaMedia (6.1)0.83%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
ModificadaMedia (4.3)0.96%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
ModificadaMedia (6.5)0.99%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
ModificadaMedia (4.3)0.92%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaAlta (7.8)0.77%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaMedia (4.3)0.93%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.
ModificadaMedia (4.3)0.92%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaAlta (7.8)0.53%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable.
ModificadaMedia (4.3)0.92%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaAlta (8.8)1.2%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.1%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
ModificadaCrítica (9.8)2.2%—PhpmyadminOpensuse Backports SLEFedoraproject FedoraOpensuse Leap22/11/201917/6/2026
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
ModificadaMedia (6.5)1.5%—Redhat AnsibleDebian LinuxOpensuse Backports SLEOpensuse Leap22/11/201917/6/2026
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
ModificadaCrítica (9.8)2.6%—Osgeo GdalOracle Spatial AND GraphDebian LinuxFedoraproject Fedora+214/10/201917/6/2026
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
ModificadaCrítica (9.8)3.1%—Nongnu LibntlmDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+210/10/201917/6/2026
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.
ModificadaAlta (7.8)0.51%—Redhat Ansible EngineDebian LinuxOpensuse Backports SLEOpensuse Leap+18/10/201917/6/2026
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are…
Orbitaley — Vulnerabilidades