Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 7.8% | 💥 PoC | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+7 | 22/7/2020 | 17/6/2026 | Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream. | |
| Modificada | Alta (8.8) | 3.0% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | |
| Modificada | Alta (8.8) | 2.9% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.7% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (7.8) | 1.6% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.4) | 0.17% | — | Google AndroidOpensuse Leap | 17/7/2020 | 17/6/2026 | In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-153467744 | |
| Modificada | Media (5.9) | 2.9% | — | Golang GOCloudfoundry Cf-deploymentCloudfoundry Routing-releaseDebian Linux+2 | 17/7/2020 | 17/6/2026 | Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time. | |
| Modificada | Media (5.3) | 1.8% | — | Golang GOOpensuse Leap | 17/7/2020 | 17/6/2026 | In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete. | |
| Modificada | Media (6.1) | 32% | — | ZabbixFedoraproject FedoraDebian LinuxOpensuse Backports+1 | 17/7/2020 | 17/6/2026 | Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget. | |
| Modificada | Media (6.7) | 1.4% | 💥 PoC | Linux KernelOpensuse LeapCanonical Ubuntu Linux | 15/7/2020 | 17/6/2026 | An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30. | |
| Modificada | Media (6.7) | 0.51% | — | Linux KernelOpensuse LeapCanonical Ubuntu Linux | 15/7/2020 | 17/6/2026 | An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032. | |
| Modificada | Media (4.4) | 0.38% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Media (4.4) | 0.38% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Alta (7.5) | 0.37% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Media (5) | 0.40% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Media (6.5) | 0.44% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Media (5) | 0.39% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Media (6) | 0.56% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Media (6) | 0.55% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Media (5.3) | 0.54% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Alta (7.5) | 0.55% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Media (5.3) | 0.54% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Media (5.3) | 0.54% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… | |
| Modificada | Media (5.3) | 0.55% | — | Oracle VM VirtualboxOpensuse Leap | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox… |