Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.8% | 💥 PoC | Roundcube WebmailDebian LinuxOpensuse Backports SLEOpensuse Leap | 4/5/2020 | 17/6/2026 | An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message. | |
| Modificada | Alta (7) | 0.31% | — | Opensuse Backports SLEFedoraproject FedoraSqliteodbc Project Sqliteodbc | 30/4/2020 | 17/6/2026 | SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library. | |
| Modificada | Media (6.1) | 2.3% | — | GNU MailmanDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+2 | 24/4/2020 | 17/6/2026 | GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME… | |
| Modificada | Alta (7.5) | 3.0% | — | TeeworldsOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+2 | 22/4/2020 | 17/6/2026 | CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server. | |
| Modificada | Alta (8.8) | 1.4% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 13/4/2020 | 17/6/2026 | Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 13/4/2020 | 17/6/2026 | Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.3) | 1.4% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.3% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+1 | 13/4/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (7.5) | 2.2% | — | Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap+1 | 8/4/2020 | 17/6/2026 | An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss. | |
| Modificada | Alta (7.5) | 1.8% | — | Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap | 8/4/2020 | 17/6/2026 | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such… | |
| Modificada | Media (5.6) | 0.71% | — | Redhat Ansible EngineRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+4 | 31/3/2020 | 17/6/2026 | A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections.… | |
| Modificada | Alta (7.5) | 2.9% | — | Gstreamer Project Gst-rtsp-serverOpensuse Backports SLEOpensuse Leap | 27/3/2020 | 17/6/2026 | An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.6% | — | OtrsOpensuse Backports SLEOpensuse LeapDebian Linux | 27/3/2020 | 17/6/2026 | It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior… | |
| Modificada | Media (4.3) | 1.3% | — | OtrsOpensuse Backports SLEOpensuse LeapDebian Linux | 27/3/2020 | 17/6/2026 | Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions. | |
| Modificada | Media (4.3) | 1.2% | — | OtrsOpensuse Backports SLEOpensuse Leap | 27/3/2020 | 17/6/2026 | In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions. | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |