Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
1671 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.65% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/5/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Alta (8) | 0.32% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/5/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption. | |
| Analizada | Alta (8.8) | 0.56% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 11/4/2025 | 17/6/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. Processing web content may lead to arbitrary code execution. | |
| Analizada | Alta (7.3) | 0.55% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 11/4/2025 | 17/6/2026 | Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. The issue was addressed with improved memory handling. | |
| Modificada | Media (6.7) | 0.58% | — | Apple SafariApple IpadosApple Iphone OSApple Macos | 31/3/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent. | |
| Modificada | Alta (7.8) | 0.26% | — | Apple VisionosApple SafariApple Iphone OSApple Ipados+1 | 31/3/2025 | 17/6/2026 | This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. An app may gain unauthorized access to Local Network. | |
| Modificada | Media (4.3) | 0.53% | — | Apple SafariApple IpadosApple Iphone OSApple Macos | 31/3/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. Visiting a malicious website may lead to address bar spoofing. | |
| Modificada | Media (4.3) | 0.82% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 31/3/2025 | 17/6/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (4.3) | 0.80% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 31/3/2025 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. A malicious website may be able to track users in Safari private browsing mode. | |
| Modificada | Crítica (9.8) | 0.92% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 31/3/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (4.3) | 0.80% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 31/3/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Alta (7.8) | 0.42% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 31/3/2025 | 17/6/2026 | This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A type confusion issue could lead to memory corruption. | |
| Modificada | Alta (7) | 0.89% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 31/3/2025 | 17/6/2026 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (6.1) | 0.57% | — | Apple SafariApple IpadosApple Iphone OS | 31/3/2025 | 17/6/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack. | |
| Modificada | Media (6.5) | 0.77% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 31/3/2025 | 17/6/2026 | A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. Visiting a website may leak sensitive data. | |
| Modificada | Alta (8.1) | 1.0% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 31/3/2025 | 17/6/2026 | The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix. | |
| Modificada | Crítica (9.8) | 0.92% | — | Apple SafariApple IpadosApple Iphone OS | 31/3/2025 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. A download's origin may be incorrectly associated. | |
| Modificada | Alta (7.5) | 0.63% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 21/3/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing web content may lead to a denial-of-service. | |
| Analizada | Crítica (10) | 3.8% | ⚠ Explotación activa💥 PoC | Apple SafariApple MacosApple VisionosApple Watchos+3 | 11/3/2025 | 17/6/2026 | An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web… | |
| Modificada | Media (6.5) | 0.63% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 10/3/2025 | 17/6/2026 | A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin. | |
| Modificada | Media (5.5) | 0.45% | — | Apple SafariApple Iphone OSApple MacosApple Tvos+2 | 10/3/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Aplazada | Alta (7.1) | 0.28% | — | Arash Safari Qmean Wordpress DID YOU MeanAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arash Safari QMean – WordPress Did You Mean qmean allows Reflected XSS.This issue affects QMean – WordPress Did You Mean: from n/a through <= 2.0. | |
| Modificada | Media (6.5) | 0.54% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 10/2/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to a denial-of-service. | |
| Modificada | Alta (7.5) | 0.77% | — | Apple SafariApple Macos | 27/1/2025 | 17/6/2026 | A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be able to bypass browser extension authentication. | |
| Modificada | Media (6.5) | 0.98% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 27/1/2025 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted web content may lead to an unexpected process crash. |