Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

424 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)10%💥 ExploitGoogle ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
ModificadaAlta (8.8)2.6%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.8%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (4.3)4.8%💥 PoCGoogle ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (8.8)2.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)7.8%💥 PoCGoogle ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+722/7/202017/6/2026
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
ModificadaAlta (8.8)3.0%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+122/7/202017/6/2026
Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaAlta (8.8)2.9%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (7.8)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.1)32%—ZabbixFedoraproject FedoraDebian LinuxOpensuse Backports+117/7/202017/6/2026
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
ModificadaAlta (7.8)0.39%—Hylafax+ Project Hylafax+Ifax Hylafax EnterpriseFedoraproject FedoraOpensuse Backports SLE+130/6/202017/6/2026
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
ModificadaCrítica (9.8)2.7%—Chocolate-doom Chocolate DoomChocolate-doom Crispy DoomOpensuse BackportsOpensuse Leap22/6/202017/6/2026
The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
ModificadaAlta (7.5)4.9%—Rubyonrails RailsDebian LinuxOpensuse Backports SLEOpensuse Leap19/6/202017/6/2026
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
ModificadaAlta (7.8)0.74%—IcingaOpensuse Backports SLEOpensuse Leap12/6/202017/6/2026
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be…
ModificadaMedia (4.4)0.36%—Linuxtv XawtvDebian LinuxOpensuse Backports SLEOpensuse Leap+28/6/202017/6/2026
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the…
ModificadaAlta (8.8)1.4%—Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap3/6/202017/6/2026
Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
ModificadaMedia (6.5)1.1%—Google ChromeDebian LinuxOpensuse BackportsOpensuse Leap3/6/202017/6/2026
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
ModificadaMedia (6.5)1.3%—Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap3/6/202017/6/2026
Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaCrítica (9.6)1.7%—Google ChromeDebian LinuxOpensuse BackportsOpensuse Leap3/6/202017/6/2026
Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
ModificadaAlta (8.2)100%💥 ExploitGrafanaFedoraproject FedoraNetapp E-series Performance AnalyzerOpensuse Leap+13/6/202017/6/2026
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running…
ModificadaMedia (5.9)1.9%—Axel Project AxelFedoraproject FedoraOpensuse Backports SLEOpensuse Leap26/5/202017/6/2026
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
ModificadaMedia (6.5)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name.
ModificadaMedia (4.3)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.
Orbitaley — Vulnerabilidades