Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

736 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.33%—Tibco Iprocess Workspace Browser10/11/202017/6/2026
The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Site Request Forgery (CSRF) attack on the affected system. A successful attack using this vulnerability requires human…
ModificadaAlta (7.5)2.2%—Browserless Chrome2/11/202017/6/2026
This affects versions of package browserless-chrome before 1.40.2-chrome-stable. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then sent back to a user. This can be escaped to fetch arbitrary files from a server.
ModificadaMedia (4.3)0.99%—Raiseitsolutions Rits Browser20/10/202017/6/2026
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser version 3.3.9 and prior versions.
ModificadaMedia (4.3)0.99%—Boltbrowser Bolt Browser20/10/202017/6/2026
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bolt Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Bolt Browser version 1.4 and prior versions.
ModificadaMedia (4.3)0.99%—Yandex Browser20/10/202017/6/2026
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Yandex Browser version 20.8.3 and prior versions, and was fixed in version 20.8.4 released…
ModificadaMedia (4.3)0.74%—Ucweb UC Browser20/10/202017/6/2026
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects UCWeb's UC Browser version 13.0.8 and prior versions.
ModificadaMedia (4.3)0.74%—Ucweb UC Browser20/10/202017/6/2026
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects UCWeb's UC Browser version 13.0.8 and prior versions.
ModificadaAlta (7.8)0.35%—360 Speed Browser3/9/202017/6/2026
360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core browser owned by Beijing Qihoo Technology.
ModificadaMedia (6.8)1.1%—Beakerbrowser Beaker26/6/202017/6/2026
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.
ModificadaMedia (5.4)0.76%—Openbrowser Project Openbrowser8/6/202017/6/2026
OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated]
ModificadaCrítica (9.1)1.1%—Naver Whale Browser Installer20/5/202017/6/2026
Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.
ModificadaBaja (3.5)1.5%—QutebrowserFedoraproject Fedora7/5/202017/6/2026
In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affected website was subsequently loaded again, the URL was mistakenly…
ModificadaCrítica (10)2.2%—Beakerbrowser Beaker23/4/202017/6/2026
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API.
ModificadaAlta (7.8)1.4%💥 PoCTencent Qqbrowser9/4/202017/6/2026
QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated Users group, which includes all local and remote users. This can be abused by local attackers to escalate privileges to NT AUTHORITY\SYSTEM by writing a malicious…
ModificadaMedia (6.5)1.2%—Greenbrowser Project Greenbrowser8/4/202017/6/2026
GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many different ways to get URL parsing and verification wrong, which allows an attacker to circumvent the access control. This problem has been patched…
ModificadaCrítica (9.8)4.2%—Op-browser Project Op-browser2/4/202017/6/2026
op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.
ModificadaMedia (5.5)0.42%—Netsurf-browser NetsurfDebian Linux21/2/202016/6/2026
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.
ModificadaAlta (7.5)2.0%—Netsurf-browser Libnsbmp18/2/202017/6/2026
libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function.
ModificadaAlta (8.8)3.1%—Netsurf-browser Libnsgif18/2/202017/6/2026
Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file.
ModificadaMedia (6.5)1.3%—Netsurf-browser Libnsgif18/2/202017/6/2026
The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file.
ModificadaCrítica (9.8)56%💥 ExploitTinybrowser12/2/202016/6/2026
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
ModificadaCrítica (9.8)9.6%💥 ExploitTinybrowser12/2/202016/6/2026
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
ModificadaAlta (8.8)3.1%—Netsurf-browser Libnsbmp12/2/202017/6/2026
Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file.
ModificadaAlta (8.8)6.2%💥 ExploitBoatmob Boat Browser12/2/202017/6/2026
The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for Android allow remote attackers to execute arbitrary code via a crafted web site, a related issue to CVE-2012-6636.
ModificadaAlta (8.8)2.6%—MI Browser10/2/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the…
Orbitaley — Vulnerabilidades