Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
23.688 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Media (5.4) | 0.21% | — | Google ChromeAI | 6/10/2026 | 6/10/2026 | UI misrepresentation in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |
| En análisis | Media (5.3) | 0.28% | — | Google ChromeAI | 6/10/2026 | 6/10/2026 | Incorrect reference resolution in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |
| En análisis | Baja (3.1) | 0.22% | — | Google ChromeAI | 6/10/2026 | 7/10/2026 | Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |
| En análisis | Media (5.4) | 0.21% | — | Google ChromeAI | 6/10/2026 | 6/10/2026 | UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |
| En análisis | Crítica (9.6) | 0.40% | — | Google ChromeAI | 6/10/2026 | 7/10/2026 | Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Alta (7.1) | 0.21% | — | Payloadcms DB MongodbAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres… | |
| Aplazada | Media (5.3) | 0.24% | — | DjangoAI | 6/10/2026 | 6/10/2026 | An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.forms.models.BaseModelFormSet.save_existing_objects()` used the presence of a primary key on a submitted form's instance as evidence that the instance belonged to the formset's limiting queryset. An object outside that… | |
| Aplazada | Media (6.9) | 0.29% | — | DjangoAI | 6/10/2026 | 6/10/2026 | An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network requests via a crafted VRT document referencing an external raster… | |
| Aplazada | Media (6.9) | 0.38% | — | DjangoAI | 6/10/2026 | 6/10/2026 | An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request… | |
| Aplazada | Media (6.9) | 0.38% | — | DjangoAI | 6/10/2026 | 6/10/2026 | An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when processing many distinct, very long language codes, which are retained as keys in an in-memory cache and… | |
| Aplazada | Alta (7.1) | 0.19% | — | Blog Posts AND Category Filter FOR ElementorAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. | |
| Aplazada | Media (5.3) | 0.26% | — | Webfactoryltd Advanced Google RecaptchaAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions. | |
| Pendiente de análisis | Baja (2.3) | 0.15% | — | Mongodb Controllers FOR KubernetesAI | 5/10/2026 | 6/10/2026 | In MongoDB Controllers for Kubernetes, insufficient validation of Ops Manager backup configuration may allow a user who can modify an OpsManager custom resource to cause unintended administrative changes in Ops Manager. This affects deployments using Enterprise Ops Manager backup reconciliation. | |
| Aplazada | Media (5.5) | 0.29% | — | Lybbn Django VUE LyadminAI | 5/10/2026 | 6/10/2026 | A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is… | |
| Aplazada | Alta (8.8) | 0.36% | — | Vektor-inc VK Google JOB Posting ManagerAI | 5/10/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1. | |
| Analizada | Alta (7) | 0.07% | — | Google Android | 5/10/2026 | 7/10/2026 | In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.5) | 0.22% | — | Google Android | 5/10/2026 | 7/10/2026 | In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.07% | — | Google Android | 5/10/2026 | 7/10/2026 | In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Baja (3.3) | 0.06% | — | Google Android | 5/10/2026 | 7/10/2026 | In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.07% | — | Google Android | 5/10/2026 | 7/10/2026 | In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.07% | — | Google Android | 5/10/2026 | 7/10/2026 | In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (8.8) | 0.23% | — | Google Android | 5/10/2026 | 7/10/2026 | In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (5.5) | 0.06% | — | Google Android | 5/10/2026 | 7/10/2026 | In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.07% | — | Google Android | 5/10/2026 | 7/10/2026 | In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.07% | — | Google Android | 5/10/2026 | 7/10/2026 | In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |