Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
4720 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.16% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 15/10/2025 | 17/6/2026 | A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to cause unexpected system termination. | |
| Modificada | Media (4.7) | 0.21% | — | Apple IpadosApple Iphone OS | 15/10/2025 | 8/10/2026 | El problema se resolvió al no cargar imágenes remotas. Este problema está solucionado en iOS 18.6 y iPadOS 18.6. Reenviar un correo electrónico podría mostrar imágenes remotas en Mail en Modo de Aislamiento. | |
| Analizada | Media (6.1) | 0.29% | — | Cisco Desk Phone 9871 FirmwareCisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 Firmware+13 | 15/10/2025 | 8/10/2026 | Una vulnerabilidad en la UI web de Cisco Desk Phone serie 9800, Cisco IP Phone series 7800 y 8800, y Cisco Video Phone 8875 que ejecutan el software Cisco SIP podría permitir a un atacante remoto no autenticado realizar ataques XSS contra un usuario de la UI web. Esta vulnerabilidad existe porque la UI web de un… | |
| Analizada | Alta (7.5) | 0.48% | — | Cisco Desk Phone 9871 FirmwareCisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 Firmware+13 | 15/10/2025 | 8/10/2026 | Una vulnerabilidad en la interfaz de usuario web de las series Cisco Desk Phone 9800, Cisco IP Phone 7800 y 8800, y Cisco Video Phone 8875 que ejecutan el software Cisco SIP podría permitir a un atacante remoto no autenticado causar una condición de DoS en un dispositivo afectado. Esta vulnerabilidad se debe a un… | |
| Modificada | Media (6.3) | 6.4% | 💥 PoC | Apple IpadosApple Iphone OSApple MacosApple Visionos | 29/9/2025 | 17/6/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 18.7.1, iOS 26.0.1 and iPadOS 26.0.1, macOS Sequoia 15.7.1, macOS Sonoma 14.8.1, macOS Tahoe 26.0.1, tvOS 26.1, visionOS 26.0.1, watchOS 26.1. Processing a maliciously crafted font may lead to… | |
| Analizada | Media (5.5) | 0.46% | — | Textit Phonenumbers | 27/9/2025 | 17/6/2026 | Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input causing a "runtime error: slice bounds out of range". | |
| Aplazada | Baja (1.9) | 0.14% | — | Ooma Office Business Phone APPAI | 19/9/2025 | 30/9/2026 | Una vulnerabilidad fue encontrada en la aplicación Ooma Office Business Phone hasta la versión 7.2.2 en Android. Esto afecta una parte desconocida del componente com.ooma.office2. La manipulación resulta en una exportación indebida de componentes de aplicaciones de Android. El ataque necesita ser abordado localmente.… | |
| Analizada | Media (6.1) | 0.26% | — | Realme Clone Phone | 18/9/2025 | 17/6/2026 | In realme BackupRestore app v15.1.12_2810c08_250314, improper URI scheme handling in com.coloros.pc.PcToolMainActivity allows local attackers to cause a crash and potential XSS via crafted ADB intents. | |
| Modificada | Alta (7.8) | 0.52% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 15/9/2025 | 17/6/2026 | The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory. | |
| Modificada | Media (4.3) | 0.77% | — | Apple SafariApple IpadosApple Iphone OSApple Macos | 15/9/2025 | 17/6/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Crítica (9.8) | 1.1% | — | Apple IpadosApple Iphone OS | 15/9/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An app may be able to monitor keystrokes without user permission. | |
| Modificada | Crítica (9.8) | 0.93% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 15/9/2025 | 17/6/2026 | A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A UDP server socket bound to a local interface may become bound to all interfaces. | |
| Modificada | Alta (8.8) | 0.30% | — | Apple IpadosApple Iphone OSApple Macos | 15/9/2025 | 17/6/2026 | A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A shortcut may be able to bypass sandbox restrictions. | |
| Modificada | Baja (3.3) | 0.23% | — | Apple IpadosApple Iphone OSApple Macos | 15/9/2025 | 17/6/2026 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to fingerprint the user. | |
| Modificada | Media (6.5) | 0.65% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 15/9/2025 | 17/6/2026 | The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A website may be able to access sensor information without user consent. | |
| Modificada | Media (5.5) | 0.23% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 15/9/2025 | 17/6/2026 | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to cause a denial-of-service. | |
| Modificada | Media (5.5) | 0.23% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 15/9/2025 | 17/6/2026 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data. | |
| Modificada | Baja (2.8) | 0.52% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 15/9/2025 | 17/6/2026 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing a maliciously crafted video file may lead to unexpected app termination. | |
| Modificada | Crítica (9.8) | 0.89% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 15/9/2025 | 17/6/2026 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An input validation issue was addressed. | |
| Modificada | Media (5.5) | 0.24% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 15/9/2025 | 17/6/2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory. | |
| Modificada | Baja (3.3) | 0.33% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 15/9/2025 | 17/6/2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to cause unexpected system termination. | |
| Modificada | Crítica (9.8) | 0.78% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+5 | 15/9/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Crítica (9.8) | 0.75% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+5 | 15/9/2025 | 17/6/2026 | A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Alta (8.8) | 0.32% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 15/9/2025 | 17/6/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, watchOS 26. An app may be able to break out of its sandbox. | |
| Modificada | Media (5.5) | 0.22% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 15/9/2025 | 17/6/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data. |