Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
16.663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.25% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium) | |
| Analizada | Alta (8.8) | 0.41% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.3) | 0.28% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Crítica (9.6) | 0.46% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Media (6.5) | 0.32% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Media (6.5) | 0.31% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium) | |
| Analizada | Media (5.3) | 0.28% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Baja (3.1) | 0.24% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.28% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Media (4.2) | 0.22% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (7.5) | 0.32% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium) | |
| Analizada | Alta (8.8) | 0.57% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (6.5) | 0.29% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Crítica (9.8) | 0.34% | — | Google Chrome | 8/9/2026 | 18/9/2026 | Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Alta (8.8) | 3.1% | ⚠ Explotación activa💥 PoC | Google Chrome | 8/9/2026 | 21/9/2026 | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Media (6.6) | 0.27% | — | Google Go-attestation | 8/9/2026 | 24/9/2026 | An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation function recurses for every nested elamAggregation sub-event without enforcing a maximum… | |
| Analizada | Crítica (10) | 0.17% | — | Google Android | 8/9/2026 | 14/9/2026 | In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (8) | 0.17% | — | Google Android | 8/9/2026 | 15/9/2026 | In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Baja (3.3) | 0.09% | — | Google Android | 8/9/2026 | 15/9/2026 | In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 8/9/2026 | 15/9/2026 | In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.09% | — | Google Android | 8/9/2026 | 15/9/2026 | In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.3) | 0.09% | — | Google Android | 8/9/2026 | 15/9/2026 | In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 8/9/2026 | 15/9/2026 | In multiple functions of RemoteViews.java, there is a possible background activity launch bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.10% | — | Google Android | 8/9/2026 | 15/9/2026 | In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Baja (3.1) | 0.20% | — | Google Android | 8/9/2026 | 15/9/2026 | In multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. |