Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1671 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 0.32% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app. | |
| Modificada | Media (6.2) | 0.99% | — | Apple SafariApple Macos | 30/7/2025 | 17/6/2026 | A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated. | |
| Modificada | Media (6.1) | 0.33% | — | Apple SafariApple Macos | 30/7/2025 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to universal cross site scripting. | |
| Modificada | Media (4.3) | 0.88% | — | Apple SafariApple IpadosApple Iphone OS | 30/7/2025 | 17/6/2026 | The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6. Visiting a malicious website may lead to address bar spoofing. | |
| Modificada | Alta (7.5) | 1.2% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose sensitive user information. | |
| Modificada | Media (6.5) | 1.1% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (6.5) | 0.98% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (6.5) | 0.74% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (6.5) | 1.0% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (6.2) | 0.40% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing web content may lead to a denial-of-service. | |
| Modificada | Alta (8.8) | 1.2% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Alta (8.8) | 1.1% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/7/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Media (6.5) | 0.57% | — | Apple SafariApple Macos | 30/7/2025 | 17/6/2026 | A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa💥 PoC | Apple SafariApple IpadosApple Iphone OSApple Macos+11 | 29/7/2025 | 21/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Analizada | Media (5.5) | 0.15% | — | Adguard FOR Safari | 17/7/2025 | 17/6/2026 | An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to read. This may be disabled in version 1.11.22. | |
| Analizada | Alta (8.8) | 9.5% | ⚠ Explotación activa💥 PoC | Google ChromeDebian LinuxApple SafariApple Ipados+6 | 15/7/2025 | 1/10/2026 | Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Crítica (9.8) | 0.30% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 29/5/2025 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A website may be able to bypass Same Origin Policy. | |
| Modificada | Alta (8.8) | 0.71% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 19/5/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Media (4.7) | 1.1% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/5/2025 | 17/6/2026 | This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Alta (7.3) | 0.96% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/5/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Alta (8) | 0.57% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/5/2025 | 15/7/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Media (6.5) | 0.65% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/5/2025 | 17/6/2026 | The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (6.5) | 0.63% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/5/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (4.3) | 0.96% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/5/2025 | 17/6/2026 | A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (6.5) | 0.38% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/5/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A malicious website may exfiltrate data cross-origin. |