Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
4720 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.23% | — | Apple IpadosApple Iphone OSApple Macos | 11/6/2026 | 7/10/2026 | Un problema de autorización se abordó con una gestión de estado mejorada. Este problema está solucionado en iOS 18.4 y iPadOS 18.4, macOS Sequoia 15.4. Una aplicación podría filtrar información sensible del usuario. | |
| Aplazada | Media (4.8) | 0.25% | — | Dovestones Softwares AdphonebookAI | 3/6/2026 | 22/7/2026 | Dovestones Softwares ADPhonebook anterior a la v4.0.1.1 es vulnerable a una vulnerabilidad de Cross Site Scripting. La API /Admin/Save permite a un usuario administrador autenticado almacenar cargas útiles de JavaScript maliciosas en múltiples secciones de configuración sin una validación de entrada adecuada ni… | |
| Aplazada | Crítica (9.8) | 0.90% | — | OTP Login With Phone NumberAI | 29/5/2026 | 21/7/2026 | El plugin OTP Login With Phone Number, OTP Verification para WordPress es vulnerable a omisión de autenticación en las versiones 1.8.50 a 1.8.60. Esto se debe a que el flujo de verificación de Firebase en el gestor AJAX 'lwp_ajax_register' no vincula la sesión de Firebase al número de teléfono proporcionado en la… | |
| Analizada | Alta (7.5) | 0.23% | — | Apple IpadosApple Iphone OS | 12/5/2026 | 7/10/2026 | Se abordó un problema de inconsistencia en la interfaz de usuario con una gestión de estado mejorada. Este problema está solucionado en iOS 18.7.3 y iPadOS 18.7.3, iOS 26.2 y iPadOS 26.2. Una aplicación podría acceder a datos sensibles del usuario. | |
| Analizada | Alta (7.5) | 0.78% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected system termination… | |
| Analizada | Media (6.2) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker on the local network may be able to cause a… | |
| Modificada | Alta (7.5) | 0.72% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 11/5/2026 | 14/9/2026 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, iOS 26.7 and iPadOS 26.7, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt… | |
| Modificada | Alta (7.5) | 0.42% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. | |
| Analizada | Media (4.7) | 0.11% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 11/5/2026 | 17/6/2026 | A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data. | |
| Modificada | Alta (7.5) | 0.54% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/8/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Analizada | Alta (7.3) | 0.39% | — | Apple IpadosApple Iphone OSApple Macos | 11/5/2026 | 17/6/2026 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Parsing a maliciously crafted file may lead to an unexpected app termination. | |
| Analizada | Alta (7.3) | 0.39% | 💥 PoC | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 11/5/2026 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or read kernel memory. | |
| Analizada | Alta (7.5) | 0.52% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to disclose kernel memory. | |
| Modificada | Media (6.2) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos | 11/5/2026 | 27/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to cause a denial-of-service. | |
| Analizada | Media (4.3) | 0.43% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing an audio stream in a maliciously crafted media file may terminate the… | |
| Modificada | Media (5.5) | 0.13% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/8/2026 | A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to access sensitive user data. | |
| Modificada | Alta (8.8) | 0.15% | 💥 PoC | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 21/8/2026 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox. | |
| Analizada | Media (5.3) | 0.32% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 11/5/2026 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An attacker in a privileged network position may be able to perform… | |
| Analizada | Media (5.5) | 0.15% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 11/5/2026 | 17/6/2026 | This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access user-sensitive data. | |
| Analizada | Media (4.7) | 0.11% | 💥 PoC | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker may be able to cause unexpected app termination. | |
| Analizada | Alta (7.5) | 0.59% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service. | |
| Modificada | Alta (7.5) | 0.52% | 💥 PoC | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/8/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory. | |
| Analizada | Media (5.5) | 0.14% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 11/5/2026 | 17/6/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An app may be able to bypass certain Privacy preferences. | |
| Analizada | Alta (7.5) | 0.51% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 11/5/2026 | 17/6/2026 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to leak sensitive kernel state. | |
| Analizada | Alta (7.5) | 0.50% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 11/5/2026 | 17/6/2026 | A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination. |