Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.63% | — | Changyou Dolphin WEB Browser | 15/5/2017 | 17/6/2026 | The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (8.1) | 0.64% | — | Browserweb INC Whizz | 24/4/2017 | 17/6/2026 | There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request. | |
| Modificada | Media (6.1) | 1.2% | — | Opera BrowserOpera Mini | 21/4/2017 | 17/6/2026 | Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL. | |
| Modificada | Media (4.7) | 1.9% | — | Brave Browser | 28/3/2017 | 17/6/2026 | Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names. | |
| Modificada | Media (6.5) | 1.6% | — | Yandex Browser | 1/3/2017 | 17/6/2026 | Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site. | |
| Modificada | Media (6.5) | 1.5% | — | Yandex Browser | 1/3/2017 | 17/6/2026 | Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site. | |
| Modificada | Alta (8.1) | 1.9% | — | TOR Browser Launcher Project TOR Browser Launcher | 7/2/2017 | 17/6/2026 | Tor Browser Launcher (aka torbrowser-launcher) before 0.2.4, during the initial run, allows man-in-the-middle attackers to bypass the PGP signature verification and execute arbitrary code via a Trojan horse tar file and a signature file with the valid tarball and signature. | |
| Modificada | Media (6.1) | 0.71% | — | Opera Browser | 26/1/2017 | 17/6/2026 | Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode characters such as U+FE70, U+0622, U+0623 etc and how they are rendered combined with (first strong character) such as an IP address or alphabet… | |
| Modificada | Media (6.1) | 0.85% | — | Yandex Browser | 26/10/2016 | 17/6/2026 | XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code. | |
| Modificada | Media (6.1) | 0.85% | — | Yandex.browser | 26/10/2016 | 17/6/2026 | XSS in Yandex Browser BookReader in Yandex browser for desktop for versions before 16.6. could be used by remote attacker for evaluation arbitrary javascript code. | |
| Modificada | Media (4.3) | 0.56% | — | Yandex Browser | 26/10/2016 | 17/6/2026 | CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile. | |
| Modificada | Alta (7.3) | 1.0% | — | Yandex Browser | 26/10/2016 | 17/6/2026 | Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript. | |
| Modificada | Alta (7.3) | 1.0% | — | Yandex Browser | 26/10/2016 | 17/6/2026 | Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript. | |
| Modificada | Media (5.3) | 1.3% | — | Yandex Browser | 26/10/2016 | 17/6/2026 | Security WiFi bypass in Yandex Browser from version 15.10 to 15.12 allows remote attacker to sniff traffic in open or WEP-protected wi-fi networks despite of special security mechanism is enabled. | |
| Modificada | Media (6.1) | 3.4% | 💥 Exploit | Browserweb Whizz | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin whizz v1.0.7 | |
| Modificada | Media (5.3) | 14% | — | Microsoft EdgeMicrosoft Internet ExplorerGoogle ChromeApple Safari+2 | 6/9/2016 | 17/6/2026 | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack. | |
| Modificada | Media (5.9) | 1.3% | — | Kaspersky Safe Browser | 25/8/2016 | 17/6/2026 | Kaspersky Safe Browser iOS before 1.7.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (8.4) | 1.4% | — | HP Ucmdb Browser | 8/1/2016 | 17/6/2026 | HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors. | |
| Modificada | Baja (3.7) | 100% | 💥 PoC | OpensslCanonical Ubuntu LinuxHp-uxIBM Content Manager+21 | 21/5/2015 | 17/6/2026 | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a… | |
| Modificada | Media (6.8) | 1.0% | — | Pictobrowser Project Pictobrowser | 31/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the PictoBrowser (pictobrowser-gallery) plugin 0.3.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the pictoBrowserFlickrUser parameter in the… | |
| Modificada | Media (5) | 1.9% | — | Maxthon Cloud Browser | 25/12/2014 | 17/6/2026 | The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API. | |
| Modificada | Media (5.4) | 0.27% | — | Cleaninternet Clean Internet Browser | 21/10/2014 | 17/6/2026 | The Clean Internet Browser (aka com.cleantab.browsesecure) application 1.36 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Live TV Browser Project Live TV Browser | 19/10/2014 | 17/6/2026 | The Live TV Browser (aka com.wHDSmartBrowser) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Cloudacl Safe Browser - THE WEB Filter | 11/10/2014 | 17/6/2026 | The Safe Browser - The Web Filter (aka com.cloudacl) application 1.2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.8) | 1.3% | — | Jigbrowser+ | 26/9/2014 | 17/6/2026 | The jigbrowser+ application 1.8.1 and earlier for iOS allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code. |