Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
2067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page. | |
| Modificada | Alta (8.8) | 3.1% | — | Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+4 | 11/2/2020 | 17/6/2026 | Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+4 | 11/2/2020 | 17/6/2026 | Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.2% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 12% | — | KDERedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server EUS+1 | 8/2/2020 | 16/6/2026 | The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion." | |
| Modificada | Crítica (9.8) | 57% | — | Nodejs Node.jsDebian LinuxFedoraproject FedoraOpensuse Leap+9 | 7/2/2020 | 17/6/2026 | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed | |
| Modificada | Alta (7.5) | 1.9% | — | Gnome EvolutionGnome Evolution Data ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 6/2/2020 | 16/6/2026 | The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain… | |
| Modificada | Alta (7.8) | 7.4% | — | Unzip Project UnzipRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+2 | 31/1/2020 | 17/6/2026 | Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. | |
| Modificada | Alta (7.8) | 7.4% | — | Unzip Project UnzipRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 31/1/2020 | 17/6/2026 | Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. | |
| Modificada | Alta (7.8) | 7.4% | — | Unzip Project UnzipRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 31/1/2020 | 17/6/2026 | Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. | |
| Modificada | Alta (7.5) | 1.6% | — | Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 31/1/2020 | 26/8/2026 | ABRT might allow attackers to obtain sensitive information from crash reports. | |
| Modificada | Baja (3.7) | 4.2% | — | Oracle JDKOracle JREOracle OpenjdkDebian Linux+19 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241 and 8u231; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java… | |
| Modificada | Baja (3.7) | 4.0% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+19 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of… | |
| Modificada | Alta (8.1) | 4.9% | — | Oracle Commerce Experience ManagerOracle Commerce Guided SearchOracle GraalvmOracle JDK+23 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Media (6.8) | 4.3% | — | Oracle JDKOracle JREOracle OpenjdkDebian Linux+19 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise… | |
| Modificada | Media (4.8) | 3.0% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+20 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.7) | 3.2% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+20 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise… | |
| Modificada | Baja (3.7) | 4.0% | — | Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+20 | 15/1/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Media (6.5) | 1.1% | — | Redhat Automatic BUG Reporting ToolRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 14/1/2020 | 17/6/2026 | daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt. | |
| Modificada | Alta (7.8) | 1.6% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+4 | 14/1/2020 | 17/6/2026 | BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address. | |
| Modificada | Alta (7.5) | 5.2% | — | Uclouvain OpenjpegFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+8 | 13/1/2020 | 22/9/2026 | OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+3 | 10/1/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.5% | — | Mozilla FirefoxMozilla Firefox ESRCanonical Ubuntu LinuxDebian Linux+8 | 8/1/2020 | 17/6/2026 | Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72. | |
| Modificada | Media (6.1) | 2.0% | — | Mozilla FirefoxMozilla Firefox ESRCanonical Ubuntu LinuxDebian Linux+5 | 8/1/2020 | 17/6/2026 | When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently… |