Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

736 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8)1.2%—MI Browser10/2/202017/6/2026
This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must connect to a malicious access point. The specific flaw exists within the handling of HTTP…
ModificadaAlta (7.8)0.52%—Avast Secure Browser27/1/202017/6/2026
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the elevated process…
ModificadaCrítica (9.8)7.8%—Apache Cordova InappbrowserOracle Instantis EnterprisetrackOracle Retail Xstore Point OF Service14/1/202017/6/2026
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
ModificadaMedia (6.1)1.8%—Avast Secure BrowserAVG Secure BrowserVideo Downloader Project Video Downloader13/1/202017/6/2026
XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute their code in the context of this component. While Video Downloader is technically a browser extension, it is granted a very wide set of privileges and can for example…
ModificadaCrítica (9.8)3.3%—Browserid Project Browserid9/1/202016/6/2026
The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.
ModificadaMedia (6.1)1.6%—Midori-browser Midori20/12/201917/6/2026
In Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the multipart/x-mixed-replace MIME type. This could result in script running where CSP should have blocked it, allowing for cross-site scripting (XSS) and other attacks when the…
ModificadaCrítica (9.8)1.9%—Maleck Image Uploader AND Browser FOR Ckeditor2/12/201917/6/2026
Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.
ModificadaAlta (7.2)2.0%—Maxthon Browser29/10/201917/6/2026
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
AnalizadaCrítica (9.8)4.9%⚠ Explotación activaTrustedconnectivityalliance S@T Browser12/9/201917/6/2026
Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.
ModificadaMedia (6.1)0.91%—Sermon Browser Project Sermon Browser21/8/201917/6/2026
The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.
ModificadaMedia (5.3)1.9%—Torproject TOR Browser30/6/201917/6/2026
Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox…
ModificadaAlta (7.8)1.7%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+1418/6/201917/6/2026
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will…
ModificadaMedia (5.3)10%💥 ExploitMI Stock BrowserRedmi 7 FirmwareRedmi Note 7 FirmwareRedmi Note 6 PRO Firmware+157/6/201917/6/2026
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
ModificadaAlta (8.8)2.4%—MI6 Browser3/6/201917/6/2026
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Mi6 Browser prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaMedia (4.3)2.2%—Torproject TOR Browser28/5/201917/6/2026
Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a "Don't send my language" setting.
ModificadaMedia (6.1)1.1%—Oculus Browser29/4/201917/6/2026
A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11.
ModificadaMedia (6.5)2.2%—MI BrowserMint Browser5/4/201917/6/2026
A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5.3 due to the way they handle the "q" query parameter. The portion of an https URL before the ?q= substring is not shown to the user.
ModificadaMedia (5.9)0.80%—Ucweb UC Browser28/3/201917/6/2026
The UCWeb UC Browser application through 2019-03-26 for Android uses HTTP to download certain modules associated with PDF and Microsoft Office files (related to libpicsel), which allows MITM attacks.
ModificadaMedia (5.9)0.72%—Ucweb UC Browser28/3/201917/6/2026
UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks.
ModificadaAlta (7.8)0.40%—Opera Browser21/3/201917/6/2026
Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it may allow the attacker to take full control of the system from any location within the system. The…
ModificadaMedia (6.5)1.4%—S3browser S3 Browser19/12/201817/6/2026
S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into connecting to a malicious server via the S3 protocol.
ModificadaAlta (7.8)0.94%—Baidu Spark Browser15/11/201817/6/2026
Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
AnalizadaAlta (8.8)60%⚠ Explotación activa💥 ExploitGoogle ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+214/11/201817/6/2026
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.5%—Samsung Internet Browser24/9/201817/6/2026
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Internet Browser Fixed in version 6.4.0.15. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaAlta (7.5)1.7%—Browserify-hot Module Replacement Project Browserify-hot Module Replacement21/9/201817/6/2026
An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://127.0.0.1:3123/ connection from any…
Orbitaley — Vulnerabilidades