Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

644 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.7%—OpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+511/12/201316/6/2026
Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
ModificadaCrítica (9.8)10%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+1211/12/201316/6/2026
Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper…
ModificadaCrítica (9.8)6.7%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+1211/12/201316/6/2026
Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors…
ModificadaCrítica (9.8)4.2%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+511/12/201316/6/2026
The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of GetElementIC typed array stubs, which has unspecified impact and remote attack vectors.
ModificadaMedia (4.3)2.4%—Mozilla FirefoxMozilla SeamonkeyFedoraproject FedoraOracle Solaris+1211/12/201316/6/2026
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.
ModificadaCrítica (9.8)9.4%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+1211/12/201316/6/2026
Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving…
ModificadaMedia (4.3)3.4%—Mozilla FirefoxMozilla SeamonkeyFedoraproject FedoraOracle Solaris+1211/12/201316/6/2026
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header.
ModificadaMedia (5.8)2.1%—Oracle SolarisFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Desktop+511/12/201316/6/2026
Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation.
ModificadaAlta (10)6.5%—Mozilla FirefoxMozilla SeamonkeyOracle SolarisFedoraproject Fedora+511/12/201316/6/2026
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
ModificadaCrítica (9.8)8.1%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+1211/12/201316/6/2026
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown…
ModificadaAlta (7.5)3.4%—PuppetPuppetlabs PuppetCanonical Ubuntu LinuxNovell Suse Linux Enterprise Desktop+219/8/201316/6/2026
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
ModificadaAlta (7.1)25%💥 PoCIBM JavaOracle JDKOracle JREOracle Jrockit+1123/7/201316/6/2026
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8…
ModificadaBaja (3.5)2.8%—Oracle SolarisOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+517/7/201316/6/2026
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
ModificadaMedia (4)2.6%—Oracle MysqlOracle SolarisOpensuseSuse Linux Enterprise Desktop+417/7/201316/6/2026
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Audit Log.
ModificadaMedia (4)2.8%—Oracle MysqlMariadbOpensuseSuse Linux Enterprise Desktop+217/7/201316/6/2026
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
ModificadaMedia (4)2.4%—Oracle MysqlOracle SolarisSuse Linux Enterprise DesktopSuse Linux Enterprise Server+317/7/201316/6/2026
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Prepared Statements.
ModificadaMedia (4)3.0%—Oracle MysqlDebian LinuxCanonical Ubuntu LinuxMariadb+417/7/201316/6/2026
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
ModificadaMedia (4)3.2%—Oracle MysqlMariadbDebian LinuxCanonical Ubuntu Linux+417/7/201316/6/2026
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Full Text Search.
ModificadaMedia (5)3.8%—Oracle MysqlOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+217/7/201316/6/2026
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
ModificadaMedia (4)2.7%—Oracle MysqlOracle SolarisOpensuseSuse Linux Enterprise Desktop+317/7/201316/6/2026
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
ModificadaMedia (4)3.1%—Oracle SolarisOracle MysqlDebian LinuxOpensuse+517/7/201316/6/2026
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
ModificadaMedia (4)3.1%—Oracle MysqlMariadbDebian LinuxCanonical Ubuntu Linux+417/7/201316/6/2026
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Parser.
AnalizadaAlta (8.8)69%⚠ Explotación activa💥 ExploitMozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRCanonical Ubuntu Linux+1126/6/201316/6/2026
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute…
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitOracle JRESUN JRESuse Linux Enterprise DesktopSuse Linux Enterprise Java+218/6/201316/6/2026
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the…
ModificadaAlta (10)5.3%—Adobe Flash PlayerAdobe AIRAdobe AIR SDKRedhat Enterprise Linux Desktop+616/5/201316/6/2026
Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler before 3.7.0.1860 allow…