Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

424 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page.
ModificadaMedia (4.3)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (6.5)1.3%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
ModificadaMedia (6.5)1.5%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to perform domain spoofing via a crafted domain name.
ModificadaMedia (6.5)1.2%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation restrictions via UI actions.
ModificadaMedia (6.5)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
ModificadaMedia (6.5)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
ModificadaAlta (7.8)0.24%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap21/5/202017/6/2026
Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privilege escalation via a crafted file.
ModificadaMedia (6.5)1.3%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Incorrect implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/5/202017/6/2026
Use after free in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.8%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+121/5/202017/6/2026
Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
ModificadaMedia (6.5)1.5%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+121/5/202017/6/2026
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory or disk via a crafted Chrome Extension.
ModificadaCrítica (9.6)1.4%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+121/5/202017/6/2026
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
ModificadaMedia (6.1)1.0%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+121/5/202017/6/2026
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents.
ModificadaCrítica (9.6)1.2%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
ModificadaAlta (8.8)6.4%💥 PoCGoogle ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+121/5/202017/6/2026
Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaCrítica (9.6)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
ModificadaCrítica (9.6)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.