Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

736 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.4%—Torproject TOR Browser14/9/201817/6/2026
Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability than CVE-2017-16541. User interaction is required to trigger this vulnerability.
ModificadaCrítica (9.8)3.1%—NoscriptTorproject TOR Browser13/9/201817/6/2026
NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value.
ModificadaMedia (5.3)2.5%—PHP File Browser Script Project PHP File Browser Script5/9/201817/6/2026
HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.
ModificadaAlta (8.8)1.2%—Qutebrowser12/7/201817/6/2026
qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, resulting in arbitrary code execution.
ModificadaMedia (6.1)1.5%—Qutebrowser26/6/201817/6/2026
qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This attack appear to be exploitable via the…
ModificadaAlta (8.8)0.74%—Microfocus Universal Cmbd Browser16/6/201817/6/2026
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).
ModificadaAlta (7.5)2.0%—Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration Mediation FulfillmentCisco Mediasense+97/6/201817/6/2026
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain…
ModificadaAlta (8.1)1.7%—Headless-browser-lite Project Headless-browser-lite1/6/201817/6/2026
headless-browser-lite is a minimal npm installer for phantomjs and slimerjs with no external dependencies. headless-browser-lite downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an…
ModificadaAlta (8.1)0.58%—Node-browser Project Node-browser1/6/201817/6/2026
node-browser is a wrapper webdriver by nodejs. node-browser downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
ModificadaMedia (5.4)0.66%—Microfocus Universal CmdbMicrofocus Universal Cmdb BrowserMicrofocus CMS Server23/5/201817/6/2026
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site…
ModificadaAlta (7.8)1.9%—Spidercontrol Scada Microbrowser26/4/201817/6/2026
In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled search path element vulnerability has been identified which could be exploited by placing a specially crafted DLL file in the search path. If the malicious DLL is loaded prior to the valid DLL, an attacker could…
ModificadaMedia (6.5)4.8%💥 ExploitBrave Browser4/4/201817/6/2026
Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaScript code, because window dialogs are mishandled.
ModificadaAlta (7.5)12%💥 ExploitBrave Browser4/4/201817/6/2026
Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.
ModificadaMedia (4.3)3.2%—Opera Browser28/3/201817/6/2026
In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.
ModificadaAlta (7.8)1.4%—Yandex Browser19/1/201817/6/2026
Yandex Browser installer for Desktop before 17.4.1 has a DLL Hijacking Vulnerability because an untrusted search path is used for dnsapi.dll, winmm.dll, ntmarta.dll, cryptbase.dll or profapi.dll.
ModificadaAlta (7.5)0.78%—Yandex Browser19/1/201817/6/2026
Race condition issue in Yandex Browser for Android before 17.4.0.16 allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page
ModificadaAlta (7.5)1.1%—Yandex Browser19/1/201817/6/2026
Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.
ModificadaAlta (7.5)1.2%—Cmcm Armorfly Browser & Downloader12/1/201817/6/2026
Cheetah Mobile Armorfly Browser & Downloader 1.1.05.0010, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass.
ModificadaAlta (7.5)1.2%—Cmcm CM Browser12/1/201817/6/2026
Cheetah Mobile CM Browser 5.22.06.0012, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass.
ModificadaMedia (5.3)5.5%💥 ExploitParity Browser11/1/201817/6/2026
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy engine (reusing the current website's token, which is not bound to an origin).
ModificadaMedia (4.7)1.0%—Brave Browser3/1/201817/6/2026
Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting blocking" component, resulting in a malicious website being able to access the fingerprinting-associated browser functionality (that the browser intends to block).
ModificadaMedia (6.1)0.94%—Samsung Internet Browser27/12/201717/6/2026
Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part of an MHTML file. Specifically, JavaScript code in another part of this MHTML file does not have a…
ModificadaAlta (7.5)79%💥 ExploitSamsung Internet Browser21/12/201717/6/2026
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.
ModificadaCrítica (9.8)8.3%—Apache Cordova In-app-browserApache Cordova30/10/201717/6/2026
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote attackers to execute arbitrary JavaScript…
ModificadaCrítica (9.8)2.6%—Spidercontrol Scada Microbrowser25/8/201717/6/2026
A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Opening a maliciously crafted html file may cause a stack overflow.
Orbitaley — Vulnerabilidades