Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.4% | — | Torproject TOR Browser | 14/9/2018 | 17/6/2026 | Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability than CVE-2017-16541. User interaction is required to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 3.1% | — | NoscriptTorproject TOR Browser | 13/9/2018 | 17/6/2026 | NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value. | |
| Modificada | Media (5.3) | 2.5% | — | PHP File Browser Script Project PHP File Browser Script | 5/9/2018 | 17/6/2026 | HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Qutebrowser | 12/7/2018 | 17/6/2026 | qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, resulting in arbitrary code execution. | |
| Modificada | Media (6.1) | 1.5% | — | Qutebrowser | 26/6/2018 | 17/6/2026 | qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This attack appear to be exploitable via the… | |
| Modificada | Alta (8.8) | 0.74% | — | Microfocus Universal Cmbd Browser | 16/6/2018 | 17/6/2026 | Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF). | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration Mediation FulfillmentCisco Mediasense+9 | 7/6/2018 | 17/6/2026 | Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain… | |
| Modificada | Alta (8.1) | 1.7% | — | Headless-browser-lite Project Headless-browser-lite | 1/6/2018 | 17/6/2026 | headless-browser-lite is a minimal npm installer for phantomjs and slimerjs with no external dependencies. headless-browser-lite downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an… | |
| Modificada | Alta (8.1) | 0.58% | — | Node-browser Project Node-browser | 1/6/2018 | 17/6/2026 | node-browser is a wrapper webdriver by nodejs. node-browser downloads resources over HTTP, which leaves it vulnerable to MITM attacks. | |
| Modificada | Media (5.4) | 0.66% | — | Microfocus Universal CmdbMicrofocus Universal Cmdb BrowserMicrofocus CMS Server | 23/5/2018 | 17/6/2026 | Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site… | |
| Modificada | Alta (7.8) | 1.9% | — | Spidercontrol Scada Microbrowser | 26/4/2018 | 17/6/2026 | In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled search path element vulnerability has been identified which could be exploited by placing a specially crafted DLL file in the search path. If the malicious DLL is loaded prior to the valid DLL, an attacker could… | |
| Modificada | Media (6.5) | 4.8% | 💥 Exploit | Brave Browser | 4/4/2018 | 17/6/2026 | Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaScript code, because window dialogs are mishandled. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Brave Browser | 4/4/2018 | 17/6/2026 | Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service. | |
| Modificada | Media (4.3) | 3.2% | — | Opera Browser | 28/3/2018 | 17/6/2026 | In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request. | |
| Modificada | Alta (7.8) | 1.4% | — | Yandex Browser | 19/1/2018 | 17/6/2026 | Yandex Browser installer for Desktop before 17.4.1 has a DLL Hijacking Vulnerability because an untrusted search path is used for dnsapi.dll, winmm.dll, ntmarta.dll, cryptbase.dll or profapi.dll. | |
| Modificada | Alta (7.5) | 0.78% | — | Yandex Browser | 19/1/2018 | 17/6/2026 | Race condition issue in Yandex Browser for Android before 17.4.0.16 allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page | |
| Modificada | Alta (7.5) | 1.1% | — | Yandex Browser | 19/1/2018 | 17/6/2026 | Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open. | |
| Modificada | Alta (7.5) | 1.2% | — | Cmcm Armorfly Browser & Downloader | 12/1/2018 | 17/6/2026 | Cheetah Mobile Armorfly Browser & Downloader 1.1.05.0010, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass. | |
| Modificada | Alta (7.5) | 1.2% | — | Cmcm CM Browser | 12/1/2018 | 17/6/2026 | Cheetah Mobile CM Browser 5.22.06.0012, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass. | |
| Modificada | Media (5.3) | 5.5% | 💥 Exploit | Parity Browser | 11/1/2018 | 17/6/2026 | Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy engine (reusing the current website's token, which is not bound to an origin). | |
| Modificada | Media (4.7) | 1.0% | — | Brave Browser | 3/1/2018 | 17/6/2026 | Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting blocking" component, resulting in a malicious website being able to access the fingerprinting-associated browser functionality (that the browser intends to block). | |
| Modificada | Media (6.1) | 0.94% | — | Samsung Internet Browser | 27/12/2017 | 17/6/2026 | Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part of an MHTML file. Specifically, JavaScript code in another part of this MHTML file does not have a… | |
| Modificada | Alta (7.5) | 79% | 💥 Exploit | Samsung Internet Browser | 21/12/2017 | 17/6/2026 | Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property. | |
| Modificada | Crítica (9.8) | 8.3% | — | Apache Cordova In-app-browserApache Cordova | 30/10/2017 | 17/6/2026 | The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote attackers to execute arbitrary JavaScript… | |
| Modificada | Crítica (9.8) | 2.6% | — | Spidercontrol Scada Microbrowser | 25/8/2017 | 17/6/2026 | A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Opening a maliciously crafted html file may cause a stack overflow. |