Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
4720 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.36% | — | Apple IpadosApple Iphone OSApple Macos | 11/5/2026 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents. | |
| Modificada | Alta (8.8) | 0.50% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 11/5/2026 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing a maliciously crafted image may corrupt process memory. | |
| Modificada | Alta (7.5) | 0.51% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 11/5/2026 | 27/7/2026 | The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Sonoma 14.8.8, macOS Tahoe 26.5, visionOS 26.5. Processing a maliciously crafted file may lead to unexpected app termination. | |
| Analizada | Alta (7.5) | 0.46% | — | Apple IpadosApple Iphone OSApple Macos | 11/5/2026 | 17/6/2026 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Replying to an email could display remote images in Mail in Lockdown Mode. | |
| Analizada | Media (6.5) | 0.38% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Visiting a maliciously crafted website may leak sensitive data. | |
| Analizada | Media (6.5) | 0.42% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Parsing a maliciously crafted file may lead to an unexpected app termination. | |
| Modificada | Media (4.3) | 0.35% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Alta (7.5) | 0.38% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 11/5/2026 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Alta (8.1) | 0.38% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. | |
| Analizada | Alta (7.5) | 0.50% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 11/5/2026 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An attacker may be able to track users through their IP address. | |
| Modificada | Alta (7.5) | 0.54% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 11/5/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Alta (7.5) | 0.54% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (6.5) | 0.51% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (6.5) | 0.51% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (4.3) | 0.51% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Media (6.2) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A local user may be able to cause unexpected system termination or read… | |
| Modificada | Alta (7.5) | 0.53% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 15/7/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Alta (7.5) | 0.37% | — | Apple IpadosApple Iphone OS | 11/5/2026 | 17/6/2026 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app may be able to circumvent App Privacy Report logging. | |
| Analizada | Alta (7.5) | 0.54% | — | Apple IpadosApple Iphone OS | 11/5/2026 | 17/6/2026 | A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service. | |
| Analizada | Alta (7.5) | 0.50% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A local attacker may be able to modify the state of the Keychain. | |
| Modificada | Alta (8.8) | 0.51% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Alta (7.5) | 0.87% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected app termination. | |
| Analizada | Media (5.4) | 0.37% | — | Apple IpadosApple Iphone OSApple Macos | 11/5/2026 | 17/6/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to execute arbitrary code with kernel privileges. | |
| Modificada | Media (6.2) | 0.19% | — | Apple IpadosApple Iphone OS | 22/4/2026 | 17/6/2026 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2, iPadOS 17.7.11. Notifications marked for deletion could be unexpectedly retained on the device. | |
| Analizada | Media (6.1) | 0.31% | — | Dovestones AD Phonebook | 21/4/2026 | 17/6/2026 | Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbitrary JavaScript in… |