Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

3145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.5%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaAlta (8.8)1.8%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
ModificadaAlta (8.8)3.9%—Google ChromeFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+1110/12/201917/6/2026
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.3%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeDebian LinuxFedoraproject FedoraNovell Suse Package HUB FOR Suse Linux Enterprise+510/12/201917/6/2026
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.6%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.4%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
ModificadaAlta (8.8)2.2%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
ModificadaAlta (8.8)2.0%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitVmware Horizon DaasVmware EsxiRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+126/12/201917/6/2026
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
ModificadaMedia (5.3)0.39%—Packagekit Project PackagekitDebian LinuxRedhat Enterprise Linux Server27/11/201916/6/2026
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
ModificadaAlta (7.8)2.3%—Artifex GhostscriptRedhat 3scale API ManagementRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+527/11/201917/6/2026
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
ModificadaAlta (8.8)1.5%—Google ChromeFedoraproject FedoraOpensuse BackportsRedhat Enterprise Linux Desktop+225/11/201917/6/2026
Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (7.8)0.49%—Linux KernelRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Power Little Endian EUSRedhat Enterprise Linux+1425/11/201917/6/2026
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
ModificadaMedia (5.5)0.27%—Redhat TunedFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+320/11/201916/6/2026
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
ModificadaMedia (6.5)0.92%—Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+77414/11/201917/6/2026
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
ModificadaMedia (6.5)3.1%—Opensuse LeapFedoraproject FedoraSlackwareHP Apollo 4200 Firmware+15614/11/201917/6/2026
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
ModificadaAlta (7.8)0.67%—Redhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUSRedhat Enterprise Linux Server TUSIntel Graphics Driver+35314/11/201917/6/2026
Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series;…
ModificadaAlta (7.8)2.2%—Icoutils Project IcoutilsRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server AUS+74/11/201917/6/2026
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
ModificadaAlta (7.8)2.1%—Icoutils Project IcoutilsRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server AUS+74/11/201917/6/2026
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
AnalizadaAlta (7.5)8.8%—ISC DhcpdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+151/11/201917/6/2026
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC…
ModificadaAlta (7.5)21%💥 PoCPythonOpensuse LeapDebian LinuxRedhat Enterprise Linux+331/10/20197/10/2026
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitPHPCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1928/10/201917/6/2026
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
ModificadaAlta (7.5)4.7%💥 PoCGolang GODebian LinuxFedoraproject FedoraRedhat Developer Tools+724/10/201917/6/2026
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.