Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering. | |
| Modificada | Alta (7.5) | 4.0% | — | Flask-cors Project Flask-corsDebian LinuxOpensuse Backports SLEOpensuse Leap | 31/8/2020 | 17/6/2026 | An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. | |
| Modificada | Alta (8) | 2.5% | — | Redhat LibrepoOpensuse Backports SLEOpensuse LeapFedoraproject Fedora | 30/8/2020 | 17/6/2026 | A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal.… | |
| Modificada | Alta (8.8) | 4.8% | 💥 PoC | Kleopatra Project KleopatraFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 29/8/2020 | 17/6/2026 | The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL. | |
| Modificada | Alta (8.8) | 3.1% | — | Fossil-scm FossilFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 25/8/2020 | 17/6/2026 | Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository. | |
| Modificada | Alta (8.8) | 4.4% | — | UI Edgeswitch FirmwareOpensuse Backports SLEOpensuse Leap | 17/8/2020 | 17/6/2026 | A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges. | |
| Modificada | Alta (7.8) | 0.36% | — | Opensuse Backports SLEOpensuse TumbleweedOpensuse Leap | 7/8/2020 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE… | |
| Modificada | Crítica (9.8) | 2.4% | — | LilypondFedoraproject FedoraDebian LinuxOpensuse Backports SLE+1 | 5/8/2020 | 17/6/2026 | scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code. | |
| Modificada | Alta (7.5) | 2.1% | — | Gnome BalsaOpensuse Backports SLEOpensuse Leap | 29/7/2020 | 17/6/2026 | In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c. | |
| Modificada | Crítica (9.8) | 2.6% | — | Claws-mailFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 23/7/2020 | 17/6/2026 | common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled. | |
| Modificada | Media (4.3) | 1.4% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA. | |
| Modificada | Media (6.1) | 1.4% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.2% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.6% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+1 | 22/7/2020 | 17/6/2026 | Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. | |
| Modificada | Media (4.3) | 1.3% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+1 | 22/7/2020 | 17/6/2026 | Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.7% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+1 | 22/7/2020 | 17/6/2026 | Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.9% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+1 | 22/7/2020 | 17/6/2026 | Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+1 | 22/7/2020 | 17/6/2026 | Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Crítica (9.6) | 1.6% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.7% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |