Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

16.665 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.33%—Google Chrome18/8/202621/8/2026
Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.53%—Google Chrome18/8/202621/8/2026
Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaMedia (6.5)0.32%—Google Chrome18/8/202621/8/2026
Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.45%—Google Chrome18/8/202620/8/2026
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.4)0.15%—Google Chrome18/8/202620/8/2026
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
AnalizadaCrítica (9.6)0.51%💥 PoCGoogle Chrome18/8/202620/8/2026
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
AnalizadaCrítica (9.6)0.46%—Google Chrome18/8/202624/8/2026
Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.57%—Google Chrome18/8/202620/8/2026
Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
AnalizadaMedia (4.2)0.22%—Google Chrome18/8/202620/8/2026
Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
AplazadaAlta (8.6)0.68%—Google ChromeAIGoogle Verified Access APIAIGoauthentik AuthentikAI18/8/20268/9/2026
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED…
AplazadaAlta (7.2)0.33%—Supsystic Easy Google MapsAI18/8/202620/8/2026
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
AplazadaCrítica (9.8)0.56%—Supsystic Easy Google MapsAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Pendiente de análisisCrítica (9.4)0.34%—Google Chronicle SoarAI17/8/202631/8/2026
A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability was patched in version 6.3.85, and no…
AplazadaMedia (6.8)0.43%💥 PoCEmbed Google Photos AlbumAI14/8/202626/8/2026
The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the…
AplazadaAlta (8.3)0.35%—BudibaseAIGoogle FirebaseAI13/8/202631/8/2026
Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend…
Pendiente de análisisAlta (7.5)0.30%—Google GOAI13/8/20263/9/2026
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been…
AplazadaCrítica (9.8)0.27%—LOG IN With GoogleAI13/8/202614/8/2026
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
Pendiente de análisisCrítica (9.9)0.65%—Google Cloud Platform GCPAIProwlerAI12/8/20269/9/2026
Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec blocks, and POST…
AnalizadaMedia (6.5)0.60%—Apache-airflow-providers-google12/8/202616/9/2026
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a…
AnalizadaAlta (8.8)0.41%—Google Chrome11/8/202617/8/2026
Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.41%—Google Chrome11/8/202617/8/2026
Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (7.5)0.27%—Google Chrome11/8/202617/8/2026
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
AnalizadaAlta (8.3)0.30%—Google Chrome11/8/202617/8/2026
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.41%—Google Chrome11/8/202617/8/2026
Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Pendiente de análisisAlta (7.5)0.16%—Google TurbiniaAI11/8/202626/8/2026
Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.