Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3303 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)1.9%—Libexif Project LibexifDebian LinuxCanonical Ubuntu LinuxOpensuse Leap21/5/202017/6/2026
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
ModificadaAlta (7.5)2.4%—Libexif Project LibexifCanonical Ubuntu LinuxOpensuse Leap21/5/202017/6/2026
An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
ModificadaCrítica (9.1)2.8%—Libexif Project LibexifDebian LinuxCanonical Ubuntu LinuxOpensuse Leap21/5/202017/6/2026
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
ModificadaMedia (6.5)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name.
ModificadaMedia (4.3)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.
ModificadaMedia (4.3)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page.
ModificadaMedia (4.3)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.3%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
ModificadaMedia (6.5)1.5%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to perform domain spoofing via a crafted domain name.
ModificadaMedia (6.5)1.2%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation restrictions via UI actions.
ModificadaMedia (6.5)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
ModificadaMedia (6.5)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
ModificadaAlta (7.8)0.24%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap21/5/202017/6/2026
Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privilege escalation via a crafted file.
ModificadaMedia (6.5)1.3%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Incorrect implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Use after free in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.8%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+121/5/202017/6/2026
Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
ModificadaMedia (6.5)1.5%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+121/5/202017/6/2026
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory or disk via a crafted Chrome Extension.
ModificadaCrítica (9.6)1.4%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+121/5/202017/6/2026
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
ModificadaMedia (6.1)1.0%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+121/5/202017/6/2026
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents.