Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

2192 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)5.1%—Gpgme Project GpgmeRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM ZRedhat Openshift Container Platform FOR Linuxone+512/2/202017/6/2026
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
ModificadaAlta (8.8)0.96%—QemuRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+211/2/202016/6/2026
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
ModificadaAlta (8.8)2.0%—Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+411/2/202017/6/2026
Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.0%—Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+411/2/202017/6/2026
Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.6%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.
ModificadaAlta (8.8)1.8%—Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+311/2/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.0%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (4.3)1.6%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaAlta (8.8)2.7%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
ModificadaMedia (6.5)2.0%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (8.8)1.8%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaMedia (6.5)1.9%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
ModificadaMedia (4.3)1.7%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaMedia (5.4)1.7%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
ModificadaMedia (6.5)1.9%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaMedia (4.3)1.5%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
ModificadaMedia (4.3)1.3%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.
ModificadaAlta (8.8)3.1%—Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+411/2/202017/6/2026
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.3%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.
ModificadaAlta (8.8)2.3%—Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+411/2/202017/6/2026
Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.2%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)12%💥 ExploitKDERedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server EUS+18/2/202016/6/2026
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
ModificadaCrítica (9.8)57%💥 PoCNodejs Node.jsDebian LinuxFedoraproject FedoraOpensuse Leap+97/2/202017/6/2026
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
ModificadaAlta (7.5)20%—Nodejs Node.jsDebian LinuxOpensuse LeapRedhat Software Collections+67/2/202017/6/2026
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
ModificadaAlta (7.5)1.9%—Gnome EvolutionGnome Evolution Data ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+16/2/202016/6/2026
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain…