Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3075▲ 488 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

23.740 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.1)0.25%—Google Chrome18/8/202621/8/2026
Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaMedia (4.3)0.33%—Google Chrome18/8/202621/8/2026
Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.53%—Google Chrome18/8/202621/8/2026
Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaMedia (6.5)0.32%—Google Chrome18/8/202621/8/2026
Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.45%—Google Chrome18/8/202620/8/2026
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.4)0.15%—Google Chrome18/8/202620/8/2026
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
AnalizadaCrítica (9.6)0.51%💥 PoCGoogle Chrome18/8/202620/8/2026
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
AnalizadaCrítica (9.6)0.46%—Google Chrome18/8/202624/8/2026
Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.57%—Google Chrome18/8/202620/8/2026
Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
AnalizadaMedia (4.2)0.22%—Google Chrome18/8/202620/8/2026
Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
AplazadaBaja (2)0.32%—Frangoteam FuxaAI18/8/20269/9/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role identifier from each user's info.roles array or the runtime usersMap cache. If a permission configuration…
AplazadaCrítica (9.2)0.69%—Frangoteam FuxaAINodered Node-redAI18/8/20269/9/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decoded identity. When nodeRedEnabled is true, secureEnabled is true, and…
AplazadaMedia (6.9)0.54%—Frangoteam FuxaAI18/8/20269/9/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/runtime/index.js return device-discovery, node-attribute, host-network-interface, and device-tag metadata without…
AplazadaMedia (6)0.46%—Frangoteam FuxaAI18/8/20269/9/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to control property.address, causing the FUXA server to issue an outbound HTTP or HTTPS request and…
AplazadaAlta (7.5)0.52%—Frangoteam FuxaAI18/8/20269/9/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including when the user is deleted or groups is zero, and POST /api/heartbeat in server/api/index.js re-signs inbound JWT…
AplazadaMedia (6.3)0.43%—Frangoteam FuxaAI18/8/20269/9/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce authJwt.haveAdminPermission for scheduler settings. An authenticated non-admin operator can create or alter deviceActions…
AplazadaMedia (5.3)0.64%—Frangoteam FuxaAITdengineAI18/8/20269/9/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape backslashes. A remote unauthenticated attacker can submit a crafted sids tag…
AplazadaAlta (8.2)0.59%—Frangoteam FuxaAI18/8/20269/9/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-controlled property.address or endpoint connection data. A remote unauthenticated…
Pendiente de análisisAlta (7.1)0.44%💥 PoCMoby Go-archiveAI18/8/202628/8/2026
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a…
AplazadaAlta (8.8)0.62%—Goauthentik AuthentikAI18/8/20268/9/2026
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings that can contain stored credentials. The…
AplazadaCrítica (9.4)0.59%—Goauthentik AuthentikAI18/8/20268/9/2026
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider's signed assertion. An attacker with an account on the source…
AplazadaMedia (5.3)0.44%—Goauthentik AuthentikAI18/8/20268/9/2026
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter used by the rest of the API. Any party able to reach the API, including an unauthenticated client, can invoke the diagnostic action…
AplazadaAlta (8.6)0.68%—Google ChromeAIGoogle Verified Access APIAIGoauthentik AuthentikAI18/8/20268/9/2026
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED…
AplazadaAlta (8.8)0.52%—DragonflyAI18/8/202610/9/2026
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose width times depth times sizeof(int64_t) overflows in src/core/cms.cc, allocating an undersized counter buffer while CMS.INCRBY and CMS.QUERY use the unbounded…
AplazadaAlta (7.2)0.33%—Supsystic Easy Google MapsAI18/8/202620/8/2026
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.