Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.4%—Mozilla FirefoxMozilla ThunderbirdDebian LinuxCanonical Ubuntu Linux+628/2/201917/6/2026
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
ModificadaCrítica (9.8)3.2%—Mozilla FirefoxMozilla ThunderbirdDebian LinuxCanonical Ubuntu Linux+628/2/201917/6/2026
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63, Firefox…
ModificadaAlta (8.8)2.3%—Mozilla FirefoxMozilla ThunderbirdDebian LinuxCanonical Ubuntu Linux+628/2/201917/6/2026
Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.3 and Thunderbird <…
ModificadaMedia (5.9)17%—OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+7827/2/201917/6/2026
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid…
ModificadaAlta (8.8)13%💥 PoCGoogle ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
ModificadaMedia (6.5)1.5%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
ModificadaAlta (7.8)0.34%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+219/2/201917/6/2026
Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.
ModificadaMedia (4.3)2.6%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.0%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome Extension.
ModificadaMedia (6.5)1.5%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+219/2/201917/6/2026
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
ModificadaMedia (6.5)1.5%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
ModificadaMedia (6.5)1.5%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
ModificadaAlta (8.8)1.5%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.
ModificadaMedia (6.5)1.8%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaAlta (8.8)3.3%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+119/2/201917/6/2026
An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
ModificadaAlta (8.8)3.0%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
ModificadaAlta (8.8)1.6%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+219/2/201917/6/2026
Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.2%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.
ModificadaMedia (6.5)1.3%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.
ModificadaMedia (6.5)1.6%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaMedia (5.5)0.54%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+219/2/201917/6/2026
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
ModificadaAlta (8.8)1.4%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Incorrect pointer management in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.6%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.7%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+219/2/201917/6/2026
Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.