Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
16.663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.41% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.34% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (6.5) | 0.23% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Baja (3.4) | 0.21% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (4.7) | 0.21% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.6) | 0.11% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.31% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Baja (3.4) | 0.21% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.4) | 0.21% | — | Google Chrome | 29/9/2026 | 30/9/2026 | UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Media (4.7) | 0.28% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (4.3) | 0.24% | — | Google Chrome | 29/9/2026 | 30/9/2026 | UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Baja (3.4) | 0.25% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (6.5) | 0.24% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Crítica (9.6) | 0.31% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Use after free in FullScreen in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.31% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (4.7) | 0.28% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.37% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.4) | 0.21% | — | Google Chrome | 29/9/2026 | 30/9/2026 | UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Crítica (9.6) | 0.31% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (4.3) | 0.28% | — | Google Chrome | 29/9/2026 | 30/9/2026 | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.35% | — | Google Chrome | 29/9/2026 | 1/10/2026 | Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.3) | 0.28% | — | Google Chrome | 29/9/2026 | 1/10/2026 | Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (4.3) | 0.28% | — | Google Chrome | 29/9/2026 | 1/10/2026 | Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.41% | — | Google Chrome | 29/9/2026 | 1/10/2026 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Pendiente de análisis | Media (6.9) | 0.09% | — | Google Osv-scalibrAI | 29/9/2026 | 30/9/2026 | A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows… |