Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 332 respecto a la semana anterior
Críticas / altas1275▼ 217 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
23.700 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.39% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Media (4.7) | 0.28% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.33% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.1) | 0.09% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.31% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.33% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.3) | 0.24% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Media (4.2) | 0.19% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Alta (8.3) | 0.27% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.31% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.31% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.41% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Baja (3.1) | 0.16% | — | Google Chrome | 15/9/2026 | 17/9/2026 | Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| Aplazada | Alta (7) | 0.28% | — | Oracle HelidonAIOracle Helidon-dbclient-mongodbAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-dbclient-mongodb). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of… | |
| Aplazada | Media (5.5) | 0.14% | — | Samsung EscargotAI | 15/9/2026 | 18/9/2026 | Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This issue affects Escargot: ac94df78493ee6fede286620d94f724e46b4d238. | |
| Analizada | Crítica (9.6) | 0.38% | — | Google Chrome | 15/9/2026 | 24/9/2026 | Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Media (4.8) | 0.19% | — | Google Chrome | 15/9/2026 | 21/9/2026 | Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium) | |
| Modificada | Alta (8.1) | 0.26% | — | Google Chrome | 15/9/2026 | 18/9/2026 | Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Baja (3.1) | 0.17% | — | Google Chrome | 15/9/2026 | 18/9/2026 | Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.1) | 0.23% | — | Google Chrome | 15/9/2026 | 18/9/2026 | Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | |
| Aplazada | Media (6.7) | 0.11% | — | Hashicorp Go-getterAI | 15/9/2026 | 19/9/2026 | The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local… | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (6.7) | 0.10% | — | Google Android | 15/9/2026 | 18/9/2026 | In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. |