Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

40.026 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.6)0.46%—Google Chrome29/9/202630/9/2026
Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
AnalizadaCrítica (9.6)0.46%—Google Chrome29/9/202630/9/2026
Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
AnalizadaCrítica (9.6)0.46%—Google Chrome29/9/202630/9/2026
Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaCrítica (9.6)0.51%—Google Chrome29/9/20261/10/2026
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
AnalizadaCrítica (9.6)0.51%—Google Chrome29/9/202630/9/2026
Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaCrítica (9.6)0.51%—Google Chrome29/9/202630/9/2026
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
AnalizadaCrítica (9.6)0.46%—Google Chrome29/9/202630/9/2026
Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaCrítica (9.1)0.68%—IBM Guardium Data Protection29/9/20262/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
Pendiente de análisisCrítica (9.3)0.25%—Microsoft Netx DUOAI29/9/202630/9/2026
NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop…
Pendiente de análisisCrítica (9.3)0.10%—Eclipse ThreadxAI29/9/202630/9/2026
Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register an arbitrary function pointer as the global trace-full callback. The kernel calls it directly —…
AnalizadaCrítica (9.5)0.39%💥 PoCBalbooa Forms29/9/20266/10/2026
Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component…
Pendiente de análisisCrítica (9.1)0.30%—Wikimedia Template SandboxAI29/9/20261/10/2026
Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10.
AplazadaCrítica (9.8)0.59%—Open Genai StackAI29/9/202630/9/2026
Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.
AplazadaCrítica (9.3)0.46%—Fumasoft Fumeng CloudAI29/9/202630/9/2026
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the…
AplazadaCrítica (9.3)0.24%—Evbee Dc-80AI29/9/202630/9/2026
The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as root using the SSH daemon that is exposed to the network.
Pendiente de análisisCrítica (9.4)0.42%—Psyb0t Docker MailboxAI29/9/202629/9/2026
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or…
AplazadaCrítica (9.3)0.26%—Dbit T-cpe301kAI29/9/202629/9/2026
A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a system reboot via a manipulated HTTP POST request directed at the endpoint ‘/js/common/do_cmd.js’ endpoint containing an excessively long parameter, which…
En análisisCrítica (9.6)0.27%—Mozilla FirefoxAI29/9/20261/10/2026
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
En análisisCrítica (9.6)0.27%—Mozilla FirefoxAI29/9/20261/10/2026
Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
AnalizadaCrítica (9.6)0.26%—Mozilla FirefoxMozilla Thunderbird29/9/20265/10/2026
Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
AnalizadaCrítica (9.6)0.26%—Mozilla FirefoxMozilla Thunderbird29/9/20265/10/2026
Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
AnalizadaCrítica (9.6)0.26%—Mozilla FirefoxMozilla Thunderbird29/9/20265/10/2026
Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
AnalizadaCrítica (9.8)0.38%—Mozilla FirefoxMozilla Thunderbird29/9/20265/10/2026
Other issue in the DevTools component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
En análisisCrítica (9.6)0.30%—Mozilla FirefoxAI29/9/202630/9/2026
Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
En análisisCrítica (9.6)0.31%—Mozilla FirefoxAI29/9/202630/9/2026
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.