Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
23.688 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.92% | — | Go-openapi SwagAI | 17/9/2026 | 22/9/2026 | go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow… | |
| Analizada | Media (6.9) | 0.40% | — | Mongodb C Driver | 17/9/2026 | 25/9/2026 | A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but does not verify that the value is at least 5 (the minimum valid BSON document size)… | |
| Analizada | Media (6.3) | 0.32% | — | Mongodb C Driver | 17/9/2026 | 25/9/2026 | A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted… | |
| Analizada | Crítica (9.2) | 0.47% | — | Mongodb C Driver | 17/9/2026 | 29/9/2026 | A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic… | |
| Analizada | Media (4.3) | 0.25% | — | Google Chrome | 17/9/2026 | 18/9/2026 | Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.4) | 0.25% | — | Google Chrome | 17/9/2026 | 18/9/2026 | UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Media (6.5) | 0.31% | — | Google Chrome | 17/9/2026 | 18/9/2026 | Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Baja (3.7) | 0.24% | — | Google Chrome | 17/9/2026 | 18/9/2026 | Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) | |
| Analizada | Media (4.3) | 0.25% | — | Google Chrome | 17/9/2026 | 18/9/2026 | Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Alta (8.8) | 0.37% | — | Google Chrome | 17/9/2026 | 19/9/2026 | Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.39% | — | Google Chrome | 17/9/2026 | 21/9/2026 | Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High) | |
| Analizada | Baja (3.1) | 0.20% | — | Google Chrome | 17/9/2026 | 21/9/2026 | Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (4.3) | 0.25% | — | Google Chrome | 17/9/2026 | 30/9/2026 | Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Baja (3.1) | 0.22% | — | Google Chrome | 17/9/2026 | 21/9/2026 | Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium) | |
| Analizada | Alta (8.8) | 0.44% | — | Google Chrome | 17/9/2026 | 21/9/2026 | Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (6.3) | 0.11% | — | Google Chrome | 17/9/2026 | 21/9/2026 | Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium) | |
| Analizada | Alta (8.1) | 0.10% | — | Google Chrome | 17/9/2026 | 21/9/2026 | Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.41% | — | Google Chrome | 17/9/2026 | 21/9/2026 | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Crítica (9.6) | 0.34% | — | Google Chrome | 17/9/2026 | 21/9/2026 | Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.45% | — | Google Chrome | 17/9/2026 | 21/9/2026 | Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| Aplazada | Baja (2.1) | 0.39% | — | Dromara Mayfly-goAI | 17/9/2026 | 17/9/2026 | A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (2.1) | 1.5% | — | Dromara Mayfly-goAI | 17/9/2026 | 22/9/2026 | A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of the argument params results in os command injection. The attack can be executed… | |
| Analizada | Media (5.7) | 0.15% | — | Mongodb Entity Framework Core Provider | 17/9/2026 | 24/9/2026 | If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys. | |
| Analizada | Media (6.8) | 0.07% | — | Mongodb Entity Framework Core Provider | 17/9/2026 | 24/9/2026 | Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption. | |
| Analizada | Media (6.8) | 0.07% | — | Mongodb Entity Framework Core Provider | 17/9/2026 | 24/9/2026 | Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database. |