Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
16.663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.28% | — | Google Android | 15/9/2026 | 21/9/2026 | In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Pendiente de análisis | Alta (8.8) | 0.75% | — | OpencostAIGoogle Cloud PlatformAI | 15/9/2026 | 30/9/2026 | OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is written to the GCP service-account… | |
| Pendiente de análisis | Alta (7.7) | 0.52% | — | Google Cloud Gemini Enterprise Agent Platform SDK FOR PythonAI | 15/9/2026 | 21/9/2026 | Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft. | |
| Pendiente de análisis | Alta (8.1) | 0.18% | — | Zscaler Client ConnectorAIGoogle AndroidAIGoogle ChromeosAI | 14/9/2026 | 18/9/2026 | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls. | |
| Aplazada | Media (4.3) | 0.10% | — | Google Site KITAI | 11/9/2026 | 11/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions. | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI | 11/9/2026 | 11/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users… | |
| Aplazada | Media (6.4) | 0.42% | — | Easy Google FontsAI | 10/9/2026 | 10/9/2026 | The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta field in all versions up to, and including, 2.0.4. This is due to the plugin registering the control_selectors meta field with show_in_rest enabled but without a sanitize_callback, and subsequently… | |
| Analizada | Media (6.9) | 0.15% | — | Google Common Expression Language | 9/9/2026 | 23/9/2026 | A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced. | |
| Pendiente de análisis | Crítica (10) | 0.74% | — | Google Cloud Agent Development KITAIPythonAI | 9/9/2026 | 9/9/2026 | A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpmr Google Feed Manager FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable to time-based SQL Injection via the 'feed' parameter in all versions up to, and including, 2.23.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Analizada | Media (4.3) | 0.24% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium) | |
| Analizada | Baja (3.1) | 0.23% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (5.4) | 0.23% | — | Google Chrome | 9/9/2026 | 14/9/2026 | Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Media (5.4) | 0.24% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Crítica (9.6) | 0.51% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.4) | 0.26% | — | Google Chrome | 9/9/2026 | 9/9/2026 | UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Baja (3.1) | 0.24% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Media (4.3) | 0.25% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.46% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (5.4) | 0.23% | — | Google Chrome | 9/9/2026 | 10/9/2026 | UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Alta (8.3) | 0.40% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Baja (3.4) | 0.25% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.53% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (5.4) | 0.23% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Alta (8.3) | 0.39% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |