Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8) | 1.2% | — | MI Browser | 10/2/2020 | 17/6/2026 | This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must connect to a malicious access point. The specific flaw exists within the handling of HTTP… | |
| Modificada | Alta (7.8) | 0.52% | — | Avast Secure Browser | 27/1/2020 | 17/6/2026 | A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the elevated process… | |
| Modificada | Crítica (9.8) | 7.8% | — | Apache Cordova InappbrowserOracle Instantis EnterprisetrackOracle Retail Xstore Point OF Service | 14/1/2020 | 17/6/2026 | A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI. | |
| Modificada | Media (6.1) | 1.8% | — | Avast Secure BrowserAVG Secure BrowserVideo Downloader Project Video Downloader | 13/1/2020 | 17/6/2026 | XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute their code in the context of this component. While Video Downloader is technically a browser extension, it is granted a very wide set of privileges and can for example… | |
| Modificada | Crítica (9.8) | 3.3% | — | Browserid Project Browserid | 9/1/2020 | 16/6/2026 | The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier. | |
| Modificada | Media (6.1) | 1.6% | — | Midori-browser Midori | 20/12/2019 | 17/6/2026 | In Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the multipart/x-mixed-replace MIME type. This could result in script running where CSP should have blocked it, allowing for cross-site scripting (XSS) and other attacks when the… | |
| Modificada | Crítica (9.8) | 1.9% | — | Maleck Image Uploader AND Browser FOR Ckeditor | 2/12/2019 | 17/6/2026 | Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code. | |
| Modificada | Alta (7.2) | 2.0% | — | Maxthon Browser | 29/10/2019 | 17/6/2026 | Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows. | |
| Analizada | Crítica (9.8) | 4.9% | ⚠ Explotación activa | Trustedconnectivityalliance S@T Browser | 12/9/2019 | 17/6/2026 | Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker. | |
| Modificada | Media (6.1) | 0.91% | — | Sermon Browser Project Sermon Browser | 21/8/2019 | 17/6/2026 | The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues. | |
| Modificada | Media (5.3) | 1.9% | — | Torproject TOR Browser | 30/6/2019 | 17/6/2026 | Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox… | |
| Modificada | Alta (7.8) | 1.7% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+14 | 18/6/2019 | 17/6/2026 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will… | |
| Modificada | Media (5.3) | 10% | 💥 Exploit | MI Stock BrowserRedmi 7 FirmwareRedmi Note 7 FirmwareRedmi Note 6 PRO Firmware+15 | 7/6/2019 | 17/6/2026 | Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request. | |
| Modificada | Alta (8.8) | 2.4% | — | MI6 Browser | 3/6/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Mi6 Browser prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Media (4.3) | 2.2% | — | Torproject TOR Browser | 28/5/2019 | 17/6/2026 | Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a "Don't send my language" setting. | |
| Modificada | Media (6.1) | 1.1% | — | Oculus Browser | 29/4/2019 | 17/6/2026 | A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11. | |
| Modificada | Media (6.5) | 2.2% | — | MI BrowserMint Browser | 5/4/2019 | 17/6/2026 | A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5.3 due to the way they handle the "q" query parameter. The portion of an https URL before the ?q= substring is not shown to the user. | |
| Modificada | Media (5.9) | 0.80% | — | Ucweb UC Browser | 28/3/2019 | 17/6/2026 | The UCWeb UC Browser application through 2019-03-26 for Android uses HTTP to download certain modules associated with PDF and Microsoft Office files (related to libpicsel), which allows MITM attacks. | |
| Modificada | Media (5.9) | 0.72% | — | Ucweb UC Browser | 28/3/2019 | 17/6/2026 | UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks. | |
| Modificada | Alta (7.8) | 0.40% | — | Opera Browser | 21/3/2019 | 17/6/2026 | Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it may allow the attacker to take full control of the system from any location within the system. The… | |
| Modificada | Media (6.5) | 1.4% | — | S3browser S3 Browser | 19/12/2018 | 17/6/2026 | S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into connecting to a malicious server via the S3 protocol. | |
| Modificada | Alta (7.8) | 0.94% | — | Baidu Spark Browser | 15/11/2018 | 17/6/2026 | Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Analizada | Alta (8.8) | 60% | ⚠ Explotación activa💥 Exploit | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 14/11/2018 | 17/6/2026 | Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.5% | — | Samsung Internet Browser | 24/9/2018 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Internet Browser Fixed in version 6.4.0.15. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Alta (7.5) | 1.7% | — | Browserify-hot Module Replacement Project Browserify-hot Module Replacement | 21/9/2018 | 17/6/2026 | An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://127.0.0.1:3123/ connection from any… |