Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.50% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/2/2026 | 17/6/2026 | A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Bluetooth packets. | |
| Modificada | Media (6.5) | 0.31% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 11/2/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Alta (7.1) | 0.14% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/2/2026 | 17/6/2026 | A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to identify what other apps a user has installed. | |
| Modificada | Media (6.5) | 0.40% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 11/2/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (4.3) | 0.31% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 11/2/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (5.5) | 0.25% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/2/2026 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted image may result in disclosure of process memory. | |
| Modificada | Alta (7.1) | 0.12% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/2/2026 | 17/6/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to break out of its sandbox. | |
| Modificada | Media (5.5) | 0.15% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 11/2/2026 | 21/8/2026 | An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3, watchOS 26.3. An app may be able to access sensitive user data. | |
| Modificada | Alta (7.8) | 0.13% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 11/2/2026 | 17/6/2026 | This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3. A malicious app may be able to gain root privileges. | |
| Modificada | Media (5.5) | 0.22% | — | Apple MacosApple Visionos | 11/2/2026 | 17/6/2026 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data. | |
| Modificada | Alta (7) | 0.11% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/2/2026 | 21/8/2026 | A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to gain root privileges. | |
| Modificada | Alta (8.8) | 0.57% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 11/2/2026 | 17/6/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. Processing a maliciously crafted USD file may lead to unexpected app termination. | |
| Modificada | Alta (7.8) | 0.17% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 11/2/2026 | 21/8/2026 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to gain root privileges. | |
| Modificada | Alta (7.8) | 0.27% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/2/2026 | 17/6/2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted media file may lead to… | |
| Modificada | Media (4.4) | 0.13% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/2/2026 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted file may lead to a denial-of-service or potentially… | |
| Modificada | Media (5.5) | 0.24% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 11/2/2026 | 15/7/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Aplazada | Crítica (9.8) | 0.34% | — | Ralim IronosAI | 27/1/2026 | 17/6/2026 | Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2. | |
| Aplazada | Media (6.9) | 0.21% | — | Ralim IronosAI | 27/1/2026 | 17/6/2026 | Vulnerability in Ralim IronOS (source/Core/BSP/Pinecilv2/bl_mcu_sdk/components/ble/ble_stack/common/tinycrypt/source modules). This vulnerability is associated with program files ecc_dsa.C. This issue affects IronOS: before v2.23-rc3. | |
| Modificada | Media (4.3) | 0.30% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 9/1/2026 | 17/6/2026 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app. | |
| Modificada | Media (6.5) | 0.39% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 9/1/2026 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Media (6.1) | 0.23% | — | Monospace Directus | 8/1/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulnerability exists in the Directus SAML authentication callback endpoint. During SAML authentication, the `RelayState` parameter is intended to preserve the user's original destination.… | |
| Aplazada | Alta (8.6) | 0.43% | — | Nrel BeoptAISdl2AIKhronos LibeglAI | 8/1/2026 | 17/6/2026 | NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking users into opening application files from remote shares. Attackers can exploit insecure library loading of sdl2.dll and libegl.dll by placing malicious libraries on WebDAV or SMB shares to execute… | |
| Modificada | Crítica (9.8) | 0.71% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 17/12/2025 | 17/6/2026 | A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Photos in the Hidden Photos Album may be viewed without authentication. | |
| Modificada | Media (5.5) | 0.17% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 17/12/2025 | 7/10/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive payment tokens. | |
| Modificada | Baja (3.3) | 0.37% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 17/12/2025 | 7/10/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to identify what other apps a user has installed. |