Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1928 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.33% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 28/10/2024 | 17/6/2026 | This issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing an image may result in disclosure of process memory. | |
| Modificada | Media (5.5) | 0.26% | — | Apple IpadosApple Iphone OSApple VisionosApple Watchos | 28/10/2024 | 17/6/2026 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1, watchOS 11.1. An app may be able to access sensitive user data. | |
| Modificada | Media (6.5) | 0.56% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 28/10/2024 | 17/6/2026 | A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, watchOS 11. Maliciously crafted web content may violate iframe sandboxing policy. | |
| Modificada | Media (5.5) | 0.30% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 28/10/2024 | 17/6/2026 | A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7.1, tvOS 18, visionOS 2, watchOS 11. Processing a maliciously crafted file may lead to unexpected app termination. | |
| Modificada | Media (5.5) | 0.29% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 24/10/2024 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (5.5) | 0.19% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 17/9/2024 | 17/6/2026 | An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (5.5) | 0.25% | — | Apple XcodeApple IpadosApple Iphone OSApple Macos+3 | 17/9/2024 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. An app may gain unauthorized access to Bluetooth. | |
| Modificada | Media (6.5) | 0.65% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 17/9/2024 | 17/6/2026 | A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin. | |
| Modificada | Media (5.5) | 0.26% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 17/9/2024 | 17/6/2026 | A logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. An app may be able to cause a denial-of-service. | |
| Modificada | Media (5.5) | 7.9% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 17/9/2024 | 17/6/2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. Processing an image may lead to a denial-of-service. | |
| Modificada | Media (4.6) | 0.28% | — | Apple IpadosApple Iphone OSApple Watchos | 17/9/2024 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. An attacker with physical access to a locked device may be able to Control Nearby Devices via accessibility features. | |
| Modificada | Media (5.5) | 0.22% | — | Apple IpadosApple Iphone OSApple MacosApple Watchos | 17/9/2024 | 17/6/2026 | A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, watchOS 11. An app may be able to access user-sensitive data. | |
| Modificada | Media (5.5) | 0.56% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 17/9/2024 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. An app may be able to cause unexpected system termination. | |
| Modificada | Media (6.1) | 0.55% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 17/9/2024 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to universal cross site scripting. | |
| Modificada | Media (5.5) | 0.27% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 17/9/2024 | 17/6/2026 | A file access issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. An app may be able to access user-sensitive data. | |
| Modificada | Media (5.5) | 0.27% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 17/9/2024 | 17/6/2026 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, tvOS 18, visionOS 2, watchOS 11. Processing a maliciously crafted file may lead to unexpected app termination. | |
| Modificada | Media (5.5) | 0.56% | — | Apple IpadosApple Iphone OSApple MacosApple Watchos | 29/7/2024 | 17/6/2026 | A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. A shortcut may be able to use sensitive data with certain actions without prompting the user. | |
| Modificada | Media (5.5) | 0.31% | — | Apple IpadosApple Iphone OSApple MacosApple Watchos | 29/7/2024 | 17/6/2026 | A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. A shortcut may be able to use sensitive data with certain actions without prompting the user. | |
| Modificada | Media (4.6) | 0.81% | — | Apple IpadosApple Iphone OSApple MacosApple Watchos | 29/7/2024 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker may be able to view restricted content from the lock screen. | |
| Modificada | Media (5.5) | 0.28% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 29/7/2024 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences. | |
| Modificada | Baja (2.4) | 0.41% | — | Apple IpadosApple Iphone OSApple MacosApple Watchos | 29/7/2024 | 17/6/2026 | This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. An attacker with physical access to a device may be able to access contacts from the lock screen. | |
| Modificada | Media (4.6) | 0.41% | — | Apple IpadosApple Iphone OSApple MacosApple Watchos | 29/7/2024 | 17/6/2026 | This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data. | |
| Modificada | Alta (7.5) | 1.1% | 💥 PoC | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 29/7/2024 | 17/6/2026 | A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. | |
| Modificada | Media (4.6) | 0.36% | — | Apple IpadosApple Iphone OSApple Watchos | 29/7/2024 | 17/6/2026 | A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data. | |
| Modificada | Alta (7.8) | 0.29% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 29/7/2024 | 17/6/2026 | A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, visionOS 1.3, watchOS 10.6. A shortcut may be able to bypass Internet permission requirements. |