Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

23.688 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisMedia (5.4)0.21%—Google ChromeAI6/10/20266/10/2026
UI misrepresentation in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
En análisisMedia (5.3)0.28%—Google ChromeAI6/10/20266/10/2026
Incorrect reference resolution in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
En análisisBaja (3.1)0.22%—Google ChromeAI6/10/20267/10/2026
Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
En análisisMedia (5.4)0.21%—Google ChromeAI6/10/20266/10/2026
UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
En análisisCrítica (9.6)0.40%—Google ChromeAI6/10/20267/10/2026
Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
En análisisAlta (7.1)0.21%—Payloadcms DB MongodbAI6/10/20266/10/2026
Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres…
AplazadaMedia (5.3)0.24%—DjangoAI6/10/20266/10/2026
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.forms.models.BaseModelFormSet.save_existing_objects()` used the presence of a primary key on a submitted form's instance as evidence that the instance belonged to the formset's limiting queryset. An object outside that…
AplazadaMedia (6.9)0.29%—DjangoAI6/10/20266/10/2026
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network requests via a crafted VRT document referencing an external raster…
AplazadaMedia (6.9)0.38%—DjangoAI6/10/20266/10/2026
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request…
AplazadaMedia (6.9)0.38%—DjangoAI6/10/20266/10/2026
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when processing many distinct, very long language codes, which are retained as keys in an in-memory cache and…
AplazadaAlta (7.1)0.19%—Blog Posts AND Category Filter FOR ElementorAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions.
AplazadaMedia (5.3)0.26%—Webfactoryltd Advanced Google RecaptchaAI6/10/20266/10/2026
Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.
Pendiente de análisisBaja (2.3)0.15%—Mongodb Controllers FOR KubernetesAI5/10/20266/10/2026
In MongoDB Controllers for Kubernetes, insufficient validation of Ops Manager backup configuration may allow a user who can modify an OpsManager custom resource to cause unintended administrative changes in Ops Manager. This affects deployments using Enterprise Ops Manager backup reconciliation.
AplazadaMedia (5.5)0.29%—Lybbn Django VUE LyadminAI5/10/20266/10/2026
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is…
AplazadaAlta (8.8)0.36%—Vektor-inc VK Google JOB Posting ManagerAI5/10/20266/10/2026
Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.
AnalizadaAlta (7)0.07%—Google Android5/10/20267/10/2026
In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.5)0.22%—Google Android5/10/20267/10/2026
In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.8)0.07%—Google Android5/10/20267/10/2026
In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaBaja (3.3)0.06%—Google Android5/10/20267/10/2026
In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.8)0.07%—Google Android5/10/20267/10/2026
In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.8)0.07%—Google Android5/10/20267/10/2026
In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (8.8)0.23%—Google Android5/10/20267/10/2026
In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaMedia (5.5)0.06%—Google Android5/10/20267/10/2026
In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.8)0.07%—Google Android5/10/20267/10/2026
In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.8)0.07%—Google Android5/10/20267/10/2026
In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.