Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.87% | — | Mitel Micloud Management Portal | 25/9/2020 | 17/6/2026 | Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization. | |
| Modificada | Media (5.5) | 1.0% | — | SqliteCanonical Ubuntu LinuxApple IcloudApple Ipados+12 | 27/6/2020 | 17/6/2026 | In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation. | |
| Modificada | Crítica (9.8) | 77% | 💥 Exploit | Apple IcloudApple ItunesApple SafariApple Ipados+3 | 9/6/2020 | 17/6/2026 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A remote attacker may be able to cause arbitrary code execution. | |
| Modificada | Alta (7.1) | 1.1% | — | Apple IcloudApple ItunesApple SafariApple Ipados+3 | 9/6/2020 | 17/6/2026 | An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to a cross site scripting… | |
| Modificada | Alta (8.8) | 1.8% | — | Apple IcloudApple ItunesApple SafariApple Ipados+3 | 9/6/2020 | 17/6/2026 | A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code… | |
| Modificada | Alta (8.8) | 1.8% | — | Apple IcloudApple ItunesApple SafariApple Ipados+3 | 9/6/2020 | 17/6/2026 | A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code… | |
| Modificada | Alta (7.1) | 1.2% | — | Apple IcloudApple ItunesApple SafariApple Ipados+3 | 9/6/2020 | 17/6/2026 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to universal cross site scripting. | |
| Modificada | Alta (8.8) | 1.8% | — | Apple IcloudApple ItunesApple SafariApple Ipados+3 | 9/6/2020 | 17/6/2026 | A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 8.3% | 💥 PoC | Apple IcloudApple ItunesApple SafariApple Ipados+3 | 9/6/2020 | 17/6/2026 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 1.6% | — | Apple IcloudApple ItunesApple SafariApple Ipados+3 | 9/6/2020 | 17/6/2026 | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Modificada | Alta (8.1) | 1.6% | — | Apple IcloudApple ItunesApple IpadosApple Iphone OS+3 | 9/6/2020 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A malicious application may cause a denial of service or potentially… | |
| Modificada | Alta (8.8) | 2.5% | — | Apple IcloudApple ItunesApple IpadosApple Iphone OS+3 | 9/6/2020 | 17/6/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code… | |
| Modificada | Alta (8.8) | 2.5% | — | Apple IcloudApple ItunesApple IpadosApple Iphone OS+3 | 9/6/2020 | 17/6/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code… | |
| Modificada | Media (5.5) | 0.62% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+14 | 27/5/2020 | 17/6/2026 | SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c. | |
| Modificada | Alta (7) | 1.0% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+15 | 27/5/2020 | 17/6/2026 | ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature. | |
| Modificada | Media (5.5) | 1.0% | — | SqliteDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+11 | 24/5/2020 | 17/6/2026 | SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c. | |
| Modificada | Media (5.5) | 1.7% | — | OpenexrFedoraproject FedoraOpensuse LeapDebian Linux+8 | 14/4/2020 | 17/6/2026 | An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read. | |
| Modificada | Media (5.5) | 1.8% | — | OpenexrFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap+8 | 14/4/2020 | 17/6/2026 | An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp. | |
| Modificada | Media (5.5) | 1.8% | — | OpenexrFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap+8 | 14/4/2020 | 17/6/2026 | An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp. | |
| Modificada | Media (5.5) | 1.8% | — | OpenexrFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap+8 | 14/4/2020 | 17/6/2026 | An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case. | |
| Modificada | Media (5.5) | 1.8% | — | OpenexrFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+7 | 14/4/2020 | 17/6/2026 | An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp. | |
| Modificada | Media (5.5) | 1.8% | — | OpenexrFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap+8 | 14/4/2020 | 17/6/2026 | An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp. | |
| Modificada | Media (5.5) | 1.7% | — | OpenexrFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+7 | 14/4/2020 | 17/6/2026 | An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer. | |
| Modificada | Media (5.5) | 1.8% | — | OpenexrFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap+8 | 14/4/2020 | 17/6/2026 | An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h. | |
| Modificada | Alta (8.8) | 1.3% | — | Apple IcloudApple ItunesApple SafariApple Ipados+2 | 1/4/2020 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to code execution. |