Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

326 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)4.8%💥 PoCKleopatra Project KleopatraFedoraproject FedoraOpensuse Backports SLEOpensuse Leap29/8/202017/6/2026
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
ModificadaAlta (8.8)3.1%—Fossil-scm FossilFedoraproject FedoraOpensuse Backports SLEOpensuse Leap25/8/202017/6/2026
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
ModificadaAlta (8.8)4.4%—UI Edgeswitch FirmwareOpensuse Backports SLEOpensuse Leap17/8/202017/6/2026
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
ModificadaAlta (7.8)0.36%—Opensuse Backports SLEOpensuse TumbleweedOpensuse Leap7/8/202017/6/2026
A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE…
ModificadaCrítica (9.8)2.4%—LilypondFedoraproject FedoraDebian LinuxOpensuse Backports SLE+15/8/202017/6/2026
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
ModificadaAlta (7.5)2.1%—Gnome BalsaOpensuse Backports SLEOpensuse Leap29/7/202017/6/2026
In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.
ModificadaCrítica (9.8)2.6%—Claws-mailFedoraproject FedoraOpensuse Backports SLEOpensuse Leap23/7/202017/6/2026
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
ModificadaMedia (4.3)1.4%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.
ModificadaMedia (6.1)1.4%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.2%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (4.3)1.6%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+122/7/202017/6/2026
Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
ModificadaMedia (4.3)1.3%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.
ModificadaMedia (4.3)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaMedia (4.3)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.9%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.7%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaCrítica (9.6)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
ModificadaAlta (8.8)2.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)10%💥 ExploitGoogle ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
ModificadaAlta (8.8)2.6%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
Orbitaley — Vulnerabilidades