Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1671 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.12% | — | Apple SafariApple IpadosApple Iphone OSApple Macos | 11/2/2026 | 17/6/2026 | A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3. An app may be able to access a user's Safari history. | |
| Modificada | Alta (7.5) | 0.63% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 11/2/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service. | |
| Modificada | Media (6.5) | 0.31% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 11/2/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (6.5) | 0.40% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 11/2/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (4.3) | 0.31% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 11/2/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (5.5) | 0.24% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 11/2/2026 | 15/7/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (4.3) | 0.30% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 9/1/2026 | 17/6/2026 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app. | |
| Modificada | Media (6.5) | 0.39% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 9/1/2026 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (5.5) | 0.16% | — | Apple SafariApple Macos | 17/12/2025 | 17/6/2026 | The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app may be able to access sensitive user data. | |
| Modificada | Media (4.3) | 0.58% | — | Apple SafariApple IpadosApple Iphone OSApple Macos | 17/12/2025 | 17/6/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Crítica (9.8) | 0.53% | — | Apple SafariApple Macos | 17/12/2025 | 17/6/2026 | This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted. | |
| Analizada | Media (4.3) | 34% | 💥 PoC | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 17/12/2025 | 7/10/2026 | A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Analizada | Media (4.3) | 0.85% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 17/12/2025 | 7/10/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Baja (3.1) | 0.45% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 17/12/2025 | 7/10/2026 | A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Alta (8.8) | 8.8% | ⚠ Explotación activa💥 PoC | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 17/12/2025 | 7/10/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of… | |
| Modificada | Media (4.3) | 0.77% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 17/12/2025 | 7/10/2026 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Alta (8.8) | 22% | ⚠ Explotación activa💥 PoC | Google ChromeApple SafariApple IpadosApple Iphone OS+5 | 12/12/2025 | 30/9/2026 | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (4.3) | 0.22% | — | Apple SafariApple Macos | 21/11/2025 | 17/6/2026 | A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window. | |
| Analizada | Alta (8.8) | 4.0% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos | 5/11/2025 | 21/9/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Alta (7.5) | 0.47% | — | Apple SafariApple IpadosApple Iphone OSApple Visionos | 4/11/2025 | 17/6/2026 | A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences. | |
| Modificada | Alta (8.1) | 0.49% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 4/11/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin. | |
| Modificada | Media (6.5) | 0.61% | — | Apple SafariApple IpadosApple Iphone OSApple Visionos+1 | 4/11/2025 | 15/7/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (4.3) | 0.96% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+1 | 4/11/2025 | 14/8/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (6.5) | 0.51% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 4/11/2025 | 17/6/2026 | This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (4.3) | 0.75% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 4/11/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash. |