Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
2067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.40% | — | Apple IcloudApple ItunesApple SafariApple Ipados+5 | 27/10/2020 | 17/6/2026 | A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin. | |
| Modificada | Alta (8.8) | 2.3% | — | Apple IcloudApple ItunesApple SafariApple Ipados+5 | 27/10/2020 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 2.3% | — | Apple IcloudApple ItunesApple SafariApple Ipados+6 | 27/10/2020 | 17/6/2026 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code… | |
| Modificada | Alta (8.8) | 2.1% | — | Apple IcloudApple ItunesApple SafariApple Ipados+5 | 27/10/2020 | 17/6/2026 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 2.7% | — | Icu-project International Components FOR UnicodeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+7 | 12/3/2020 | 17/6/2026 | An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp. | |
| Analizada | Alta (8.8) | 79% | ⚠ Explotación activa | Google ChromeFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 27/2/2020 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 27/2/2020 | 17/6/2026 | Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 27/2/2020 | 17/6/2026 | Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 6.4% | — | Google ChromeFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 27/2/2020 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 10% | — | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 13/2/2020 | 17/6/2026 | Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.96% | — | QemuRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 11/2/2020 | 16/6/2026 | The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read. | |
| Modificada | Alta (8.8) | 2.0% | — | Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+4 | 11/2/2020 | 17/6/2026 | Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.0% | — | Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+4 | 11/2/2020 | 17/6/2026 | Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.6% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.8% | — | Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+3 | 11/2/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.0% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.6% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. | |
| Modificada | Media (6.5) | 2.0% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.8% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | |
| Modificada | Media (6.5) | 1.9% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.7% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Media (5.4) | 1.7% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.9% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.5% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. |