Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.8% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (4.3) | 4.8% | 💥 PoC | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 7.8% | 💥 PoC | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+7 | 22/7/2020 | 17/6/2026 | Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream. | |
| Modificada | Alta (8.8) | 3.0% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | |
| Modificada | Alta (8.8) | 2.9% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.7% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (7.8) | 1.6% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 22/7/2020 | 17/6/2026 | Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (7.8) | 0.39% | — | Hylafax+ Project Hylafax+Ifax Hylafax EnterpriseFedoraproject FedoraOpensuse Backports SLE+1 | 30/6/2020 | 17/6/2026 | In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root. | |
| Modificada | Alta (7.5) | 4.9% | — | Rubyonrails RailsDebian LinuxOpensuse Backports SLEOpensuse Leap | 19/6/2020 | 17/6/2026 | A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters. | |
| Modificada | Alta (7.8) | 0.74% | — | IcingaOpensuse Backports SLEOpensuse Leap | 12/6/2020 | 17/6/2026 | An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be… | |
| Modificada | Media (4.4) | 0.36% | — | Linuxtv XawtvDebian LinuxOpensuse Backports SLEOpensuse Leap+2 | 8/6/2020 | 17/6/2026 | An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the… | |
| Modificada | Alta (8.8) | 1.4% | — | Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap | 3/6/2020 | 17/6/2026 | Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.3% | — | Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap | 3/6/2020 | 17/6/2026 | Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Alta (8.2) | 100% | 💥 Exploit | GrafanaFedoraproject FedoraNetapp E-series Performance AnalyzerOpensuse Leap+1 | 3/6/2020 | 17/6/2026 | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running… | |
| Modificada | Media (5.9) | 1.9% | — | Axel Project AxelFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 26/5/2020 | 17/6/2026 | An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/5/2020 | 17/6/2026 | Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name. | |
| Modificada | Media (4.3) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/5/2020 | 17/6/2026 | Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.6% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/5/2020 | 17/6/2026 | Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.6% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/5/2020 | 17/6/2026 | Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.6% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/5/2020 | 17/6/2026 | Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.7% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/5/2020 | 17/6/2026 | Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.7% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/5/2020 | 17/6/2026 | Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/5/2020 | 17/6/2026 | Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request. | |
| Modificada | Media (6.5) | 1.7% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/5/2020 | 17/6/2026 | Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |