Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1930 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.5%—Google ChromeDebian LinuxSuse Package HUBOpensuse Backports SLE+410/12/201917/6/2026
Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaMedia (6.5)1.4%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaMedia (6.5)1.3%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page.
ModificadaMedia (6.5)1.3%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
ModificadaAlta (8.8)1.1%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.
ModificadaMedia (6.5)0.85%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
ModificadaMedia (6.5)1.3%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
ModificadaMedia (6.5)1.3%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page.
ModificadaMedia (6.5)1.4%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaAlta (8.8)1.8%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
ModificadaAlta (8.8)3.9%—Google ChromeFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+1110/12/201917/6/2026
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.3%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeDebian LinuxFedoraproject FedoraNovell Suse Package HUB FOR Suse Linux Enterprise+510/12/201917/6/2026
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.6%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.4%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
ModificadaAlta (8.8)2.2%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
ModificadaAlta (8.8)2.0%—Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+310/12/201917/6/2026
Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitVmware Horizon DaasVmware EsxiRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+126/12/201917/6/2026
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
ModificadaAlta (7.8)2.3%—Artifex GhostscriptRedhat 3scale API ManagementRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+527/11/201917/6/2026
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
ModificadaAlta (8.8)1.5%—Google ChromeFedoraproject FedoraOpensuse BackportsRedhat Enterprise Linux Desktop+225/11/201917/6/2026
Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (5.5)0.27%—Redhat TunedFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+320/11/201916/6/2026
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
ModificadaMedia (6.5)3.1%—Opensuse LeapFedoraproject FedoraSlackwareHP Apollo 4200 Firmware+15614/11/201917/6/2026
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
ModificadaAlta (7.8)2.2%—Icoutils Project IcoutilsRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server AUS+74/11/201917/6/2026
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.