Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
321 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 5.4% | — | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | |
| Modificada | Alta (8.8) | 6.5% | — | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 5.9% | — | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension. | |
| Modificada | Media (6.5) | 8.7% | — | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. | |
| Modificada | Alta (8.1) | 8.1% | — | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | |
| Modificada | Crítica (9.6) | 7.9% | — | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Media (6.5) | 11% | 💥 PoC | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | |
| Modificada | Alta (8.8) | 7.0% | — | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Crítica (9.6) | 6.2% | — | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Alta (8.8) | 6.9% | — | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 6.8% | — | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 17% | — | Google ChromeMicrosoft Edge Chromium | 9/2/2021 | 17/6/2026 | Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | |
| Analizada | Alta (8.8) | 48% | ⚠ Explotación activa | CefsharpGoogle ChromeMicrosoft EdgeMicrosoft Edge Chromium+4 | 3/11/2020 | 17/6/2026 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.9% | — | Apple Iphone OSApple MAC OS XChromiumDebian Linux+3 | 3/4/2018 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | |
| Modificada | Alta (7.5) | 1.2% | — | Google ChromeChromiumCanonical Ubuntu LinuxGoogle V8 | 22/1/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | |
| Modificada | Alta (7.5) | 1.8% | — | Canonical Ubuntu LinuxGoogle ChromeChromium | 22/1/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | |
| Modificada | Media (5) | 1.6% | — | Canonical Ubuntu LinuxOpensuseRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server Supplementary+4 | 22/1/2015 | 17/6/2026 | Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.6% | — | ChromiumRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+4 | 22/1/2015 | 17/6/2026 | The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Media (5) | 1.6% | — | ChromiumRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+3 | 22/1/2015 | 17/6/2026 | The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted X11 data. | |
| Modificada | Media (4.3) | 2.5% | — | Google ChromeChromiumRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server Supplementary+3 | 22/1/2015 | 17/6/2026 | Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header. | |
| Modificada | Alta (9.3) | 4.4% | — | Chromium Project ChromiumApple SafariApple Webkit | 21/7/2011 | 16/6/2026 | WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1. |