Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
10.010 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.68% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 25% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 29% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 15% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.85% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.87% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |
| Modificada | Alta (7.8) | 0.49% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H410c Firmware+3 | 15/5/2023 | 17/6/2026 | An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Alta (7.5) | 6.1% | — | Linux KernelRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 9/5/2023 | 17/6/2026 | A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the… | |
| Modificada | Alta (7.5) | 2.2% | — | FrroutingDebian LinuxFedoraproject Fedora | 9/5/2023 | 17/6/2026 | Un problema encontrado en Frrouting bgpd v.8.4.2 permite a un atacante remoto causar una denegación de servicio a través de la función bgp_attr_psid_sub(). | |
| Modificada | Alta (7.5) | 1.1% | — | MaradnsFedoraproject FedoraDebian Linux | 9/5/2023 | 17/6/2026 | MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attacker to cause a Denial of Service by triggering an abnormal program termination. The vulnerability… | |
| Modificada | Media (6.5) | 0.93% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 8/5/2023 | 17/6/2026 | The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4. A website may be able to track sensitive user information. | |
| Modificada | Media (5.5) | 0.20% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 8/5/2023 | 17/6/2026 | This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy. | |
| Modificada | Media (6.5) | 2.1% | — | FrroutingDebian Linux | 3/5/2023 | 17/6/2026 | Existe una lectura fuera de los límites en el daemon BGP de FRRouting FRR hasta 8.4. Al enviar un mensaje BGP OPEN con formato incorrecto que termina con el octeto de longitud de la opción (o la palabra de longitud de la opción, en el caso de un mensaje OPEN extendido), el código FRR se lee fuera de los límites del… | |
| Modificada | Media (6.5) | 2.0% | — | FrroutingDebian Linux | 3/5/2023 | 17/6/2026 | Se descubrió un problema en bgpd en FRRouting (FRR) hasta 8.4. Al manipular un mensaje BGP OPEN con una opción de tipo 0xff (longitud extendida de RFC 9072), los atacantes pueden provocar una denegación de servicio (fallo de aserción y reinicio del servicio, o lectura fuera de límites). Esto es posible debido a… | |
| Modificada | Media (6.5) | 2.0% | — | FrroutingDebian Linux | 3/5/2023 | 17/6/2026 | Se descubrió un problema en bgpd en FRRouting (FRR) a través de 8.4. Al crear un mensaje BGP OPEN con una opción de tipo 0xff (longitud extendida de RFC 9072), los atacantes pueden provocar una denegación de servicio (error de aserción y reinicio del servicio, o lectura fuera de los límites). Esto es posible debido a… | |
| Modificada | Media (4.3) | 0.80% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (4.3) | 0.82% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (4.3) | 0.80% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (4.3) | 0.97% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (4.3) | 0.65% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (4.3) | 0.86% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (4.3) | 0.80% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.76% | — | Google ChromeDebian LinuxFedoraproject Fedora | 3/5/2023 | 17/6/2026 | Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium) | |
| Modificada | Alta (7.1) | 0.69% | — | Google ChromeDebian LinuxFedoraproject Fedora | 3/5/2023 | 17/6/2026 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.97% | — | Google ChromeDebian LinuxFedoraproject Fedora | 3/5/2023 | 17/6/2026 | Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML page. (Chromium security severity: Medium) |