Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.18% | — | Paloaltonetworks Prisma Access BrowserAI | 11/4/2025 | 17/6/2026 | An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions. | |
| Aplazada | Alta (7.8) | 0.34% | — | Spatie BrowsershotAI | 4/4/2025 | 17/6/2026 | Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories. | |
| Aplazada | Media (5.4) | 0.14% | — | Tobias Merz Browser Caching With .htaccessAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in tobias_.MerZ Browser Caching with .htaccess allows Cross Site Request Forgery. This issue affects Browser Caching with .htaccess: from 1.2.1 through n/a. | |
| Aplazada | Alta (7.1) | 0.18% | — | Mendibass Browser Address BAR ColorAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mendibass Browser Address Bar Color browser-address-bar-color allows Stored XSS.This issue affects Browser Address Bar Color: from n/a through <= 3.3. | |
| Aplazada | Alta (7.1) | 0.28% | — | Michael Stursberg Browser-update-notifyAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Stursberg Browser-Update-Notify browser-update-notify allows Reflected XSS.This issue affects Browser-Update-Notify: from n/a through <= 0.2.1. | |
| Aplazada | Media (5.3) | 0.41% | — | TU Yafeng VIA BrowserAI | 27/2/2025 | 17/6/2026 | A vulnerability was found in Tu Yafeng Via Browser up to 5.9.0 on Android. It has been rated as problematic. This issue affects some unknown processing of the component Javascript Bridge. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2.7) | 0.21% | — | Revoworks ScvxAIRevoworks BrowserAI | 26/2/2025 | 17/6/2026 | Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using the product. | |
| Aplazada | Media (6.5) | 0.40% | — | VIA BrowserAI | 24/2/2025 | 17/6/2026 | An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component. | |
| Aplazada | Media (6.6) | 0.55% | — | Spatie BrowsershotAI | 5/2/2025 | 17/6/2026 | Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method, which results in a Local File Inclusion allowing the attacker to read sensitive files. **Note:** This is a bypass of the fix for… | |
| Aplazada | Alta (7.8) | 0.46% | — | Spatie BrowsershotAI | 5/2/2025 | 15/7/2026 | Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by omitting the slashes in the file URI (e.g., file:../../../../etc/passwd). This is due to missing validations of the user input that… | |
| Aplazada | Crítica (9.9) | 0.65% | — | Enrico Sandoli Smallerik File BrowserAI | 22/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-browser allows Upload a Web Shell to a Web Server.This issue affects Smallerik File Browser: from n/a through <= 1.1. | |
| Aplazada | Media (6.1) | 0.36% | — | Brave BrowserAI | 21/1/2025 | 17/6/2026 | On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When combined with an open redirector vulnerability… | |
| Aplazada | Media (4.7) | 0.13% | — | Lenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI | 14/1/2025 | 17/6/2026 | A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash. | |
| Aplazada | Media (4.7) | 0.12% | — | Lenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI | 14/1/2025 | 17/6/2026 | A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash. | |
| Analizada | Baja (3.8) | 0.26% | — | Browser Back Button Project Browser Back Button | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: from 1.0.0 before 2.0.2. | |
| Aplazada | Media (6.6) | 0.61% | — | Spatie BrowsershotAI | 20/12/2024 | 6/8/2026 | Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file. **Note:** This is a bypass of… | |
| Aplazada | Alta (7.7) | 0.95% | — | Spatie BrowsershotAI | 18/12/2024 | 17/6/2026 | Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\. An attacker could read any file on the server by exploiting the normalization of \ into /. | |
| Aplazada | Media (6.6) | 0.57% | — | Spatie BrowsershotAI | 13/12/2024 | 17/6/2026 | Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local File Inclusion, which allows the attacker… | |
| Aplazada | Alta (8.1) | 0.35% | — | Superfast Video DownloaderAIBluesky BrowserAI | 11/11/2024 | 17/6/2026 | The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component. | |
| Aplazada | Media (5.4) | 0.24% | — | DS Allvideo.downloader.browserAI | 11/11/2024 | 17/6/2026 | The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component. | |
| Aplazada | Alta (8.1) | 0.34% | — | Apptool Browser Video ALL Video DownloaderAI | 30/10/2024 | 17/6/2026 | The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component. | |
| Aplazada | Media (6.3) | 0.28% | — | Naver Whale Browser InstallerAI | 25/10/2024 | 17/6/2026 | Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings. | |
| Aplazada | Media (5.4) | 0.39% | 💥 PoC | Temenos T24 BrowserAI | 23/9/2024 | 5/7/2026 | A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.jsp and genrequest.jsp components. | |
| Analizada | Alta (8.4) | 0.71% | 💥 PoC | Yandex Browser | 3/9/2024 | 17/6/2026 | Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used. | |
| Modificada | Media (6.1) | 0.42% | 💥 PoC | Heytap Internet Browser | 19/8/2024 | 17/6/2026 | The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity component. |