Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

326 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.8%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (4.3)4.8%💥 PoCGoogle ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (8.8)2.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)7.8%💥 PoCGoogle ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+722/7/202017/6/2026
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
ModificadaAlta (8.8)3.0%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+122/7/202017/6/2026
Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaAlta (8.8)2.9%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (7.8)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (7.8)0.39%—Hylafax+ Project Hylafax+Ifax Hylafax EnterpriseFedoraproject FedoraOpensuse Backports SLE+130/6/202017/6/2026
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
ModificadaAlta (7.5)4.9%—Rubyonrails RailsDebian LinuxOpensuse Backports SLEOpensuse Leap19/6/202017/6/2026
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
ModificadaAlta (7.8)0.74%—IcingaOpensuse Backports SLEOpensuse Leap12/6/202017/6/2026
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be…
ModificadaMedia (4.4)0.36%—Linuxtv XawtvDebian LinuxOpensuse Backports SLEOpensuse Leap+28/6/202017/6/2026
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the…
ModificadaAlta (8.8)1.4%—Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap3/6/202017/6/2026
Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
ModificadaMedia (6.5)1.3%—Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap3/6/202017/6/2026
Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaAlta (8.2)100%💥 ExploitGrafanaFedoraproject FedoraNetapp E-series Performance AnalyzerOpensuse Leap+13/6/202017/6/2026
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running…
ModificadaMedia (5.9)1.9%—Axel Project AxelFedoraproject FedoraOpensuse Backports SLEOpensuse Leap26/5/202017/6/2026
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
ModificadaMedia (6.5)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name.
ModificadaMedia (4.3)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.
ModificadaMedia (4.3)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page.
ModificadaMedia (4.3)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Orbitaley — Vulnerabilidades