Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
2304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.26% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 15/9/2025 | 17/6/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to cause unexpected system termination. | |
| Modificada | Media (6.5) | 1.0% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 15/9/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (5.5) | 0.27% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 15/9/2025 | 17/6/2026 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data. | |
| Modificada | Crítica (9.8) | 1.6% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 15/9/2025 | 17/6/2026 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, watchOS 26. An app may be able to access sensitive user data. | |
| Aplazada | Media (6.9) | 0.45% | — | Watchguard Fireware OSAI | 15/9/2025 | 10/8/2026 | An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack. WatchGuard does not believe there is a practical exploit chain with a meaningful… | |
| Aplazada | Media (4.8) | 0.48% | — | Watchguard FireboxAI | 15/9/2025 | 8/8/2026 | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface… | |
| Aplazada | Baja (3.3) | 0.12% | — | Samsung Galaxy WatchAIGoogle Android WatchAI | 6/8/2025 | 17/6/2026 | Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information. | |
| Aplazada | Media (6.2) | 0.14% | — | Samsung Galaxy WatchAI | 6/8/2025 | 17/6/2026 | Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time. | |
| Aplazada | Media (5.5) | 0.12% | — | Samsung Galaxy WatchAI | 6/8/2025 | 17/6/2026 | Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration. | |
| Aplazada | Media (5.5) | 0.13% | — | Samsung Galaxy WatchAI | 6/8/2025 | 17/6/2026 | Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to motion and body sensors. | |
| Modificada | Media (4) | 0.32% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app. | |
| Modificada | Crítica (9.8) | 1.00% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 30/7/2025 | 17/6/2026 | Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted texture may lead to unexpected app termination. | |
| Modificada | Media (4) | 0.21% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 30/7/2025 | 17/6/2026 | The issue was addressed with additional permissions checks. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to access user-sensitive data. | |
| Modificada | Alta (7.5) | 1.2% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose sensitive user information. | |
| Modificada | Media (4) | 0.23% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 30/7/2025 | 17/6/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted image may result in disclosure of process memory. | |
| Modificada | Alta (7.5) | 0.97% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 30/7/2025 | 17/6/2026 | A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. A non-privileged user may be able to modify restricted network settings. | |
| Modificada | Media (6.5) | 1.1% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (6.5) | 0.98% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (6.5) | 0.74% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (6.5) | 1.0% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (6.2) | 0.40% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing web content may lead to a denial-of-service. | |
| Modificada | Crítica (9.8) | 0.90% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 30/7/2025 | 17/6/2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari… | |
| Modificada | Crítica (9.8) | 1.1% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Parsing a file may lead to an unexpected app termination. | |
| Modificada | Alta (8.8) | 1.2% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Alta (8.8) | 1.1% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. |