Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.33% | — | Tibco Iprocess Workspace Browser | 10/11/2020 | 17/6/2026 | The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Site Request Forgery (CSRF) attack on the affected system. A successful attack using this vulnerability requires human… | |
| Modificada | Alta (7.5) | 2.2% | — | Browserless Chrome | 2/11/2020 | 17/6/2026 | This affects versions of package browserless-chrome before 1.40.2-chrome-stable. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then sent back to a user. This can be escaped to fetch arbitrary files from a server. | |
| Modificada | Media (4.3) | 0.99% | — | Raiseitsolutions Rits Browser | 20/10/2020 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser version 3.3.9 and prior versions. | |
| Modificada | Media (4.3) | 0.99% | — | Boltbrowser Bolt Browser | 20/10/2020 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bolt Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Bolt Browser version 1.4 and prior versions. | |
| Modificada | Media (4.3) | 0.99% | — | Yandex Browser | 20/10/2020 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Yandex Browser version 20.8.3 and prior versions, and was fixed in version 20.8.4 released… | |
| Modificada | Media (4.3) | 0.74% | — | Ucweb UC Browser | 20/10/2020 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects UCWeb's UC Browser version 13.0.8 and prior versions. | |
| Modificada | Media (4.3) | 0.74% | — | Ucweb UC Browser | 20/10/2020 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects UCWeb's UC Browser version 13.0.8 and prior versions. | |
| Modificada | Alta (7.8) | 0.35% | — | 360 Speed Browser | 3/9/2020 | 17/6/2026 | 360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core browser owned by Beijing Qihoo Technology. | |
| Modificada | Media (6.8) | 1.1% | — | Beakerbrowser Beaker | 26/6/2020 | 17/6/2026 | The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution. | |
| Modificada | Media (5.4) | 0.76% | — | Openbrowser Project Openbrowser | 8/6/2020 | 17/6/2026 | OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated] | |
| Modificada | Crítica (9.1) | 1.1% | — | Naver Whale Browser Installer | 20/5/2020 | 17/6/2026 | Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer. | |
| Modificada | Baja (3.5) | 1.5% | — | QutebrowserFedoraproject Fedora | 7/5/2020 | 17/6/2026 | In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affected website was subsequently loaded again, the URL was mistakenly… | |
| Modificada | Crítica (10) | 2.2% | — | Beakerbrowser Beaker | 23/4/2020 | 17/6/2026 | Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API. | |
| Modificada | Alta (7.8) | 1.4% | 💥 PoC | Tencent Qqbrowser | 9/4/2020 | 17/6/2026 | QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated Users group, which includes all local and remote users. This can be abused by local attackers to escalate privileges to NT AUTHORITY\SYSTEM by writing a malicious… | |
| Modificada | Media (6.5) | 1.2% | — | Greenbrowser Project Greenbrowser | 8/4/2020 | 17/6/2026 | GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many different ways to get URL parsing and verification wrong, which allows an attacker to circumvent the access control. This problem has been patched… | |
| Modificada | Crítica (9.8) | 4.2% | — | Op-browser Project Op-browser | 2/4/2020 | 17/6/2026 | op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function. | |
| Modificada | Media (5.5) | 0.42% | — | Netsurf-browser NetsurfDebian Linux | 21/2/2020 | 16/6/2026 | Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar. | |
| Modificada | Alta (7.5) | 2.0% | — | Netsurf-browser Libnsbmp | 18/2/2020 | 17/6/2026 | libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function. | |
| Modificada | Alta (8.8) | 3.1% | — | Netsurf-browser Libnsgif | 18/2/2020 | 17/6/2026 | Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file. | |
| Modificada | Media (6.5) | 1.3% | — | Netsurf-browser Libnsgif | 18/2/2020 | 17/6/2026 | The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file. | |
| Modificada | Crítica (9.8) | 56% | 💥 Exploit | Tinybrowser | 12/2/2020 | 16/6/2026 | TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. | |
| Modificada | Crítica (9.8) | 9.6% | 💥 Exploit | Tinybrowser | 12/2/2020 | 16/6/2026 | Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution. | |
| Modificada | Alta (8.8) | 3.1% | — | Netsurf-browser Libnsbmp | 12/2/2020 | 17/6/2026 | Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file. | |
| Modificada | Alta (8.8) | 6.2% | 💥 Exploit | Boatmob Boat Browser | 12/2/2020 | 17/6/2026 | The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for Android allow remote attackers to execute arbitrary code via a crafted web site, a related issue to CVE-2012-6636. | |
| Modificada | Alta (8.8) | 2.6% | — | MI Browser | 10/2/2020 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the… |