Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

736 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.18%—Paloaltonetworks Prisma Access BrowserAI11/4/202517/6/2026
An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions.
AplazadaAlta (7.8)0.34%—Spatie BrowsershotAI4/4/202517/6/2026
Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories.
AplazadaMedia (5.4)0.14%—Tobias Merz Browser Caching With .htaccessAI28/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in tobias_.MerZ Browser Caching with .htaccess allows Cross Site Request Forgery. This issue affects Browser Caching with .htaccess: from 1.2.1 through n/a.
AplazadaAlta (7.1)0.18%—Mendibass Browser Address BAR ColorAI24/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in mendibass Browser Address Bar Color browser-address-bar-color allows Stored XSS.This issue affects Browser Address Bar Color: from n/a through <= 3.3.
AplazadaAlta (7.1)0.28%—Michael Stursberg Browser-update-notifyAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Stursberg Browser-Update-Notify browser-update-notify allows Reflected XSS.This issue affects Browser-Update-Notify: from n/a through <= 0.2.1.
AplazadaMedia (5.3)0.41%—TU Yafeng VIA BrowserAI27/2/202517/6/2026
A vulnerability was found in Tu Yafeng Via Browser up to 5.9.0 on Android. It has been rated as problematic. This issue affects some unknown processing of the component Javascript Bridge. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public…
AplazadaBaja (2.7)0.21%—Revoworks ScvxAIRevoworks BrowserAI26/2/202517/6/2026
Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using the product.
AplazadaMedia (6.5)0.40%—VIA BrowserAI24/2/202517/6/2026
An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.
AplazadaMedia (6.6)0.55%—Spatie BrowsershotAI5/2/202517/6/2026
Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method, which results in a Local File Inclusion allowing the attacker to read sensitive files. **Note:** This is a bypass of the fix for…
AplazadaAlta (7.8)0.46%—Spatie BrowsershotAI5/2/202515/7/2026
Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by omitting the slashes in the file URI (e.g., file:../../../../etc/passwd). This is due to missing validations of the user input that…
AplazadaCrítica (9.9)0.65%—Enrico Sandoli Smallerik File BrowserAI22/1/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-browser allows Upload a Web Shell to a Web Server.This issue affects Smallerik File Browser: from n/a through <= 1.1.
AplazadaMedia (6.1)0.36%—Brave BrowserAI21/1/202517/6/2026
On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When combined with an open redirector vulnerability…
AplazadaMedia (4.7)0.13%—Lenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI14/1/202517/6/2026
A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.
AplazadaMedia (4.7)0.12%—Lenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI14/1/202517/6/2026
A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.
AnalizadaBaja (3.8)0.26%—Browser Back Button Project Browser Back Button9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: from 1.0.0 before 2.0.2.
AplazadaMedia (6.6)0.61%—Spatie BrowsershotAI20/12/20246/8/2026
Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file. **Note:** This is a bypass of…
AplazadaAlta (7.7)0.95%—Spatie BrowsershotAI18/12/202417/6/2026
Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\. An attacker could read any file on the server by exploiting the normalization of \ into /.
AplazadaMedia (6.6)0.57%—Spatie BrowsershotAI13/12/202417/6/2026
Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local File Inclusion, which allows the attacker…
AplazadaAlta (8.1)0.35%—Superfast Video DownloaderAIBluesky BrowserAI11/11/202417/6/2026
The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component.
AplazadaMedia (5.4)0.24%—DS Allvideo.downloader.browserAI11/11/202417/6/2026
The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component.
AplazadaAlta (8.1)0.34%—Apptool Browser Video ALL Video DownloaderAI30/10/202417/6/2026
The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component.
AplazadaMedia (6.3)0.28%—Naver Whale Browser InstallerAI25/10/202417/6/2026
Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings.
AplazadaMedia (5.4)0.39%💥 PoCTemenos T24 BrowserAI23/9/20245/7/2026
A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.jsp and genrequest.jsp components.
AnalizadaAlta (8.4)0.71%💥 PoCYandex Browser3/9/202417/6/2026
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
ModificadaMedia (6.1)0.42%💥 PoCHeytap Internet Browser19/8/202417/6/2026
The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity component.