Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.5% | — | Google ChromeDebian LinuxSuse Package HUBOpensuse Backports SLE+4 | 10/12/2019 | 17/6/2026 | Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (8.8) | 3.9% | — | Google ChromeFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+11 | 10/12/2019 | 17/6/2026 | Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (7.8) | 0.76% | — | Shadowsocks-libevOpensuse Backports SLEOpensuse Leap | 3/12/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability. | |
| Modificada | Media (6.5) | 1.7% | — | Redhat AnsibleOpensuse Backports SLEOpensuse LeapRedhat Openstack | 26/11/2019 | 17/6/2026 | ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None | |
| Modificada | Media (4.3) | 1.2% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page. | |
| Modificada | Media (4.3) | 0.88% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. | |
| Modificada | Media (4.3) | 1.0% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page. | |
| Modificada | Media (4.3) | 0.93% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (4.3) | 0.85% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. | |
| Modificada | Media (6.1) | 0.83% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL. | |
| Modificada | Media (4.3) | 0.96% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page. | |
| Modificada | Media (6.5) | 0.99% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page. | |
| Modificada | Media (4.3) | 0.92% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Alta (7.8) | 0.77% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | |
| Modificada | Media (4.3) | 0.93% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. | |
| Modificada | Media (4.3) | 0.92% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Alta (7.8) | 0.53% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable. | |
| Modificada | Media (4.3) | 0.92% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.2% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Crítica (9.8) | 2.2% | — | PhpmyadminOpensuse Backports SLEFedoraproject FedoraOpensuse Leap | 22/11/2019 | 17/6/2026 | An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature. | |
| Modificada | Media (6.5) | 1.5% | — | Redhat AnsibleDebian LinuxOpensuse Backports SLEOpensuse Leap | 22/11/2019 | 17/6/2026 | ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them. | |
| Modificada | Crítica (9.8) | 2.6% | — | Osgeo GdalOracle Spatial AND GraphDebian LinuxFedoraproject Fedora+2 | 14/10/2019 | 17/6/2026 | GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded. | |
| Modificada | Crítica (9.8) | 3.1% | — | Nongnu LibntlmDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+2 | 10/10/2019 | 17/6/2026 | Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request. | |
| Modificada | Alta (7.8) | 0.51% | — | Redhat Ansible EngineDebian LinuxOpensuse Backports SLEOpensuse Leap+1 | 8/10/2019 | 17/6/2026 | In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are… |