Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

326 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.25%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux3/11/202017/6/2026
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker to bypass navigation restrictions via crafted Intents.
ModificadaAlta (8.8)1.6%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE3/11/202017/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE3/11/202017/6/2026
Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.5%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE3/11/202017/6/2026
Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora3/11/202017/6/2026
Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.4%—Google ChromeFedoraproject FedoraOpensuse Backports SLEDebian Linux3/11/202017/6/2026
Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora3/11/202017/6/2026
Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.
ModificadaMedia (6.5)1.0%—Google ChromeFedoraproject FedoraOpensuse Backports SLEDebian Linux3/11/202017/6/2026
Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension.
ModificadaAlta (8.8)2.5%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE3/11/202017/6/2026
Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.4%—Google ChromeFedoraproject FedoraOpensuse Backports SLEDebian Linux3/11/202017/6/2026
Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
ModificadaAlta (8.8)1.4%—Google ChromeFedoraproject FedoraOpensuse Backports SLEDebian Linux3/11/202017/6/2026
Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+63/11/202017/6/2026
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE3/11/202017/6/2026
Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.4%—Google ChromeFedoraproject FedoraOpensuse Backports SLEDebian Linux3/11/202017/6/2026
Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
ModificadaAlta (7.5)6.5%—Powerdns RecursorOpensuse Backports SLEOpensuse Leap16/10/202017/6/2026
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of…
ModificadaCrítica (9.3)2.0%—Sylabs SingularityOpensuse Backports SLEOpensuse Leap14/10/202017/6/2026
Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to overwrite/create any files on the host filesystem during the extraction with a crafted squashfs…
ModificadaCrítica (9.8)67%💥 ExploitPhpmyadminOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+110/10/202017/6/2026
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.
ModificadaMedia (6.1)1.9%—PhpmyadminOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+110/10/202017/6/2026
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
ModificadaMedia (5.5)0.55%—KdeconnectOpensuse Backports SLEOpensuse Leap7/10/202017/6/2026
In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.
ModificadaCrítica (9.8)9.2%💥 PoCZabbixOpensuse Backports SLEOpensuse LeapDebian Linux7/10/202017/6/2026
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
ModificadaMedia (5.3)1.9%—Nextcloud Preferred ProvidersOpensuse Backports SLEOpensuse Leap5/10/202017/6/2026
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
ModificadaMedia (6.1)0.97%—Redhat PagureOpensuse Backports SLEOpensuse Leap25/9/202017/6/2026
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
ModificadaAlta (8.8)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/9/202017/6/2026
Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.3)1.4%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/9/202017/6/2026
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
ModificadaAlta (7.8)0.36%—Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux+121/9/202017/6/2026
Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary.
Orbitaley — Vulnerabilidades