Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2734▼ 7 respecto a la semana anterior
Críticas / altas1273▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

10.167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.93%—Apple SafariApple IpadosApple Iphone OSApple Macos+38/5/202317/6/2026
The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4. A website may be able to track sensitive user information.
ModificadaMedia (5.5)0.20%—Apple SafariApple IpadosApple Iphone OSApple Macos+38/5/202317/6/2026
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy.
ModificadaMedia (6.5)2.1%—FrroutingDebian Linux3/5/202317/6/2026
Existe una lectura fuera de los límites en el daemon BGP de FRRouting FRR hasta 8.4. Al enviar un mensaje BGP OPEN con formato incorrecto que termina con el octeto de longitud de la opción (o la palabra de longitud de la opción, en el caso de un mensaje OPEN extendido), el código FRR se lee fuera de los límites del…
ModificadaMedia (6.5)2.0%—FrroutingDebian Linux3/5/202317/6/2026
Se descubrió un problema en bgpd en FRRouting (FRR) hasta 8.4. Al manipular un mensaje BGP OPEN con una opción de tipo 0xff (longitud extendida de RFC 9072), los atacantes pueden provocar una denegación de servicio (fallo de aserción y reinicio del servicio, o lectura fuera de límites). Esto es posible debido a…
ModificadaMedia (6.5)2.0%—FrroutingDebian Linux3/5/202317/6/2026
Se descubrió un problema en bgpd en FRRouting (FRR) a través de 8.4. Al crear un mensaje BGP OPEN con una opción de tipo 0xff (longitud extendida de RFC 9072), los atacantes pueden provocar una denegación de servicio (error de aserción y reinicio del servicio, o lectura fuera de los límites). Esto es posible debido a…
ModificadaMedia (4.3)0.80%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)
ModificadaMedia (4.3)0.82%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low)
ModificadaMedia (4.3)0.80%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)
ModificadaMedia (4.3)0.97%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (4.3)0.65%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (4.3)0.86%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (4.3)0.80%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.76%—Google ChromeDebian LinuxFedoraproject Fedora3/5/202317/6/2026
Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)
ModificadaAlta (7.1)0.69%—Google ChromeDebian LinuxFedoraproject Fedora3/5/202317/6/2026
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.97%—Google ChromeDebian LinuxFedoraproject Fedora3/5/202317/6/2026
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (4.7)0.72%—Linux KernelDebian Linux26/4/202317/6/2026
A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend upgrading past version 6.1.8 or commit…
ModificadaAlta (7.5)2.4%💥 PoCLinux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+425/4/202317/6/2026
The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the…
ModificadaMedia (4.4)0.22%—Linux KernelFedoraproject FedoraDebian LinuxNetapp H300s Firmware+425/4/20238/10/2026
A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component.
ModificadaAlta (7.8)0.29%—Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+424/4/202317/6/2026
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
ModificadaMedia (6.5)1.0%—Xmlsoft Libxml2Debian Linux24/4/202317/6/2026
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of…
ModificadaMedia (6.5)0.94%—Xmlsoft Libxml2Debian Linux24/4/202317/6/2026
In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.
ModificadaMedia (5.5)0.41%—Linux KernelFedoraproject FedoraDebian LinuxNetapp H410c Firmware24/4/202317/6/2026
An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fepriv,events). In dvb_frontend_test_event, down(&fepriv->sem)…
ModificadaMedia (5.6)1.4%💥 ExploitLinux KernelDebian Linux21/4/202317/6/2026
The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least one major cloud provider, the kernel still left the victim process exposed to attacks in some cases…
ModificadaAlta (8.8)1.1%—Google ChromeDebian LinuxFedoraproject Fedora19/4/202317/6/2026
Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
AnalizadaCrítica (9.6)5.7%⚠ Explotación activaGoogle ChromeDebian LinuxFedoraproject Fedora19/4/202317/6/2026
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)