Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1654 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.40%—Apple SafariApple IpadosApple Iphone OSApple Macos+111/2/202615/7/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
ModificadaMedia (4.3)0.31%—Apple SafariApple IpadosApple Iphone OSApple Macos+311/2/202615/7/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
ModificadaMedia (5.5)0.25%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/2/202617/6/2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted image may result in disclosure of process memory.
ModificadaAlta (7.1)0.12%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/2/202617/6/2026
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to break out of its sandbox.
ModificadaMedia (5.5)0.15%—Apple IpadosApple Iphone OSApple MacosApple Visionos+111/2/202621/8/2026
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3, watchOS 26.3. An app may be able to access sensitive user data.
ModificadaAlta (7.8)0.13%—Apple IpadosApple Iphone OSApple MacosApple Visionos11/2/202617/6/2026
This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3. A malicious app may be able to gain root privileges.
ModificadaMedia (5.5)0.22%—Apple MacosApple Visionos11/2/202617/6/2026
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
ModificadaAlta (7)0.11%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/2/202621/8/2026
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to gain root privileges.
ModificadaAlta (8.8)0.57%—Apple IpadosApple Iphone OSApple MacosApple Visionos11/2/202617/6/2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. Processing a maliciously crafted USD file may lead to unexpected app termination.
ModificadaAlta (7.8)0.17%—Apple IpadosApple Iphone OSApple MacosApple Visionos11/2/202621/8/2026
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to gain root privileges.
ModificadaAlta (7.8)0.27%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/2/202617/6/2026
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted media file may lead to…
ModificadaMedia (4.4)0.13%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/2/202617/6/2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted file may lead to a denial-of-service or potentially…
ModificadaMedia (5.5)0.24%—Apple SafariApple IpadosApple Iphone OSApple Macos+111/2/202615/7/2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
AplazadaAlta (7.2)0.91%💥 PoCHikvision Wireless Access PointAI30/1/202617/6/2026
Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
AnalizadaAlta (8.5)0.29%—Cvat Computer Vision Annotation Tool21/1/202617/6/2026
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may freely change their permissions, including giving themselves superuser status and joining the admin group, which gives them full access to the data in the CVAT…
AnalizadaAlta (8.6)0.17%—Cvat Computer Vision Annotation Tool21/1/202617/6/2026
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a victim user's CVAT UI session, provided that they are able to create a maliciously crafted label in a CVAT task or project, then get the…
AplazadaAlta (8.7)2.9%💥 ExploitGeovision GeowebserverAI16/1/202617/6/2026
GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and…
AplazadaAlta (8.8)0.35%💥 PoCHikvision NVRAIHikvision DVRAIHikvision CVRAIHikvision IPCAI13/1/20269/7/2026
There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.
ModificadaAlta (8.8)0.47%—Hikvision Ds-k1t331 FirmwareHikvision Ds-k1t341a FirmwareHikvision Ds-k1t341b FirmwareHikvision Ds-k1t671 Firmware+2413/1/20269/7/2026
There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.
ModificadaMedia (4.3)0.30%—Apple SafariApple IpadosApple Iphone OSApple Macos+39/1/202617/6/2026
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.
ModificadaMedia (6.5)0.39%—Apple SafariApple IpadosApple Iphone OSApple Macos+39/1/202617/6/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
AnalizadaMedia (6.6)0.12%—Qualcomm Sa6150p FirmwareQualcomm Sa6155 FirmwareQualcomm Sa6155p FirmwareQualcomm Sa7255p Firmware+2357/1/20267/10/2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
AplazadaMedia (4.8)0.22%—Stvs ProvisionAI31/12/202517/6/2026
STVS ProVision 5.9.10 contains a cross-site scripting vulnerability in the 'files' POST parameter that allows authenticated attackers to inject arbitrary HTML code. Attackers can exploit the unvalidated input to execute malicious scripts within a user's browser session in the context of the affected site.
AplazadaMedia (5.1)0.24%—Netvision Information IsoinsightAI30/12/20257/10/2026
ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
AnalizadaMedia (5.8)0.20%—Hanwhavision Xno-8082r FirmwareHanwhavision Xnv-8082r FirmwareHanwhavision Xnd-8082rf FirmwareHanwhavision Xnd-8082rv Firmware+25226/12/20257/10/2026
Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered that validation of incoming XML format request messages is inadequate. This vulnerability could allow an attacker to XSS on the user's browser. The manufacturer has…
Orbitaley — Vulnerabilidades