Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 10% | 💥 Exploit | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.6% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+1 | 22/7/2020 | 17/6/2026 | Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.8% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (4.3) | 4.8% | 💥 PoC | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 7.8% | 💥 PoC | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+7 | 22/7/2020 | 17/6/2026 | Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream. | |
| Modificada | Alta (8.8) | 3.0% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | |
| Modificada | Alta (8.8) | 2.9% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.7% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (7.8) | 1.6% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.1) | 32% | — | ZabbixFedoraproject FedoraDebian LinuxOpensuse Backports+1 | 17/7/2020 | 17/6/2026 | Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget. | |
| Modificada | Alta (7.8) | 0.39% | — | Hylafax+ Project Hylafax+Ifax Hylafax EnterpriseFedoraproject FedoraOpensuse Backports SLE+1 | 30/6/2020 | 17/6/2026 | In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root. | |
| Modificada | Crítica (9.8) | 2.7% | — | Chocolate-doom Chocolate DoomChocolate-doom Crispy DoomOpensuse BackportsOpensuse Leap | 22/6/2020 | 17/6/2026 | The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack. | |
| Modificada | Alta (7.5) | 4.9% | — | Rubyonrails RailsDebian LinuxOpensuse Backports SLEOpensuse Leap | 19/6/2020 | 17/6/2026 | A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters. | |
| Modificada | Alta (7.8) | 0.74% | — | IcingaOpensuse Backports SLEOpensuse Leap | 12/6/2020 | 17/6/2026 | An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be… | |
| Modificada | Media (4.4) | 0.36% | — | Linuxtv XawtvDebian LinuxOpensuse Backports SLEOpensuse Leap+2 | 8/6/2020 | 17/6/2026 | An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the… | |
| Modificada | Alta (8.8) | 1.4% | — | Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap | 3/6/2020 | 17/6/2026 | Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.1% | — | Google ChromeDebian LinuxOpensuse BackportsOpensuse Leap | 3/6/2020 | 17/6/2026 | Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. | |
| Modificada | Media (6.5) | 1.3% | — | Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap | 3/6/2020 | 17/6/2026 | Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Crítica (9.6) | 1.7% | — | Google ChromeDebian LinuxOpensuse BackportsOpensuse Leap | 3/6/2020 | 17/6/2026 | Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Alta (8.2) | 100% | 💥 Exploit | GrafanaFedoraproject FedoraNetapp E-series Performance AnalyzerOpensuse Leap+1 | 3/6/2020 | 17/6/2026 | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running… | |
| Modificada | Media (5.9) | 1.9% | — | Axel Project AxelFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 26/5/2020 | 17/6/2026 | An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/5/2020 | 17/6/2026 | Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name. | |
| Modificada | Media (4.3) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/5/2020 | 17/6/2026 | Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page. |