Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)14%⚠ Explotación activaApple IpadosApple Iphone OSApple MAC OS XApple Macos+42/4/202117/6/2026
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code…
ModificadaMedia (6.5)1.4%—Apple MAC OS XApple MacosFedoraproject FedoraWebkitgtk2/4/202117/6/2026
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Maliciously crafted web content may violate iframe sandboxing policy.
ModificadaBaja (3.3)0.36%—Apple IpadosApple Iphone OSApple MAC OS XApple Macos+32/4/202117/6/2026
"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. A user may be unable to fully delete browsing history.
ModificadaAlta (8.8)1.9%—Webkitgtk3/3/202117/6/2026
A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially crafted web page can lead to a use after free.
ModificadaAlta (7.8)1.4%—Apple IcloudApple ItunesApple SafariApple Ipados+78/12/202017/6/2026
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
ModificadaAlta (8.8)4.9%—WebkitgtkFedoraproject Fedora3/12/202017/6/2026
An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in a remote code execution. The victim needs to visit a malicious web site to trigger this vulnerability.
ModificadaAlta (8.8)3.5%—Webkitgtk3/12/202017/6/2026
A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web page can trigger a use-after-free vulnerability which can lead to remote code execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
ModificadaAlta (7.1)1.5%—Apple IcloudApple SafariApple IpadosApple Iphone OS+316/10/202017/6/2026
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0, iCloud for Windows 11.4, iCloud for Windows 7.21. Processing maliciously crafted web content may lead to a cross site scripting attack.
ModificadaAlta (8.8)2.3%—Apple IcloudApple ItunesApple SafariApple Ipados+516/10/202017/6/2026
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
ModificadaAlta (8.8)1.7%—Apple SafariWebkitgtk+Debian Linux16/10/202017/6/2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
ModificadaCrítica (10)3.3%—WebkitgtkWpewebkit WPE WebkitFedoraproject FedoraDebian Linux+214/7/202017/6/2026
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the…
ModificadaAlta (8.8)2.9%—WebkitgtkWpewebkit WPE WebkitCanonical Ubuntu LinuxFedoraproject Fedora+117/4/202017/6/2026
A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).
ModificadaCrítica (9.8)5.0%—WebkitgtkWpewebkit WPE WebkitFedoraproject FedoraDebian Linux+22/3/202017/6/2026
WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.
ModificadaMedia (6.1)1.4%—Apple IcloudApple ItunesApple SafariApple Ipados+427/2/202017/6/2026
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to universal cross site scripting.
ModificadaMedia (5.3)1.4%—Webkitgtk17/2/202017/6/2026
Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpectedly high sound volume via malicious javascript. NOTE: this WebKit-GTK behavior complies with existing W3C standards and existing practices for GNOME desktop integration.
ModificadaAlta (8.8)1.4%—Webkitgtk+Canonical Ubuntu Linux22/1/202017/6/2026
WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS
ModificadaMedia (6.1)1.3%—Apple IcloudApple ItunesApple SafariApple Ipados+318/12/201917/6/2026
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.
ModificadaMedia (6.1)0.97%—Apple WatchosWebkitgtk+18/12/201917/6/2026
A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.
ModificadaMedia (6.1)1.3%—Apple IcloudApple ItunesWebkitgtk+18/12/201917/6/2026
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.
ModificadaMedia (6.1)1.0%—Apple SafariApple Iphone OSWebkitgtk18/12/201917/6/2026
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
ModificadaMedia (6.1)1.2%—Apple IcloudApple ItunesWebkitgtk+18/12/201917/6/2026
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.
ModificadaMedia (5.3)3.3%—WebkitgtkWpewebkit WPE Webkit10/4/201917/6/2026
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
ModificadaAlta (8.8)1.8%—Apple SafariApple Iphone OSApple TvosApple Icloud+25/3/201917/6/2026
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
ModificadaCrítica (9.8)16%💥 ExploitWebkitgtkWebkitgtk+Opensuse LeapCanonical Ubuntu Linux24/2/201917/6/2026
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact,…
ModificadaAlta (8.1)4.3%—Gnome EpiphanyWebkitgtkWpewebkit WPE WebkitFedoraproject Fedora+214/1/201917/6/2026
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.