Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3075▲ 488 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
23.740 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.1) | 0.25% | — | Google Chrome | 18/8/2026 | 21/8/2026 | Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (4.3) | 0.33% | — | Google Chrome | 18/8/2026 | 21/8/2026 | Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.53% | — | Google Chrome | 18/8/2026 | 21/8/2026 | Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (6.5) | 0.32% | — | Google Chrome | 18/8/2026 | 21/8/2026 | Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.45% | — | Google Chrome | 18/8/2026 | 20/8/2026 | Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.4) | 0.15% | — | Google Chrome | 18/8/2026 | 20/8/2026 | Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.51% | 💥 PoC | Google Chrome | 18/8/2026 | 20/8/2026 | Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Crítica (9.6) | 0.46% | — | Google Chrome | 18/8/2026 | 24/8/2026 | Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.57% | — | Google Chrome | 18/8/2026 | 20/8/2026 | Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Media (4.2) | 0.22% | — | Google Chrome | 18/8/2026 | 20/8/2026 | Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | |
| Aplazada | Baja (2) | 0.32% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role identifier from each user's info.roles array or the runtime usersMap cache. If a permission configuration… | |
| Aplazada | Crítica (9.2) | 0.69% | — | Frangoteam FuxaAINodered Node-redAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decoded identity. When nodeRedEnabled is true, secureEnabled is true, and… | |
| Aplazada | Media (6.9) | 0.54% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/runtime/index.js return device-discovery, node-attribute, host-network-interface, and device-tag metadata without… | |
| Aplazada | Media (6) | 0.46% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to control property.address, causing the FUXA server to issue an outbound HTTP or HTTPS request and… | |
| Aplazada | Alta (7.5) | 0.52% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including when the user is deleted or groups is zero, and POST /api/heartbeat in server/api/index.js re-signs inbound JWT… | |
| Aplazada | Media (6.3) | 0.43% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce authJwt.haveAdminPermission for scheduler settings. An authenticated non-admin operator can create or alter deviceActions… | |
| Aplazada | Media (5.3) | 0.64% | — | Frangoteam FuxaAITdengineAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape backslashes. A remote unauthenticated attacker can submit a crafted sids tag… | |
| Aplazada | Alta (8.2) | 0.59% | — | Frangoteam FuxaAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-controlled property.address or endpoint connection data. A remote unauthenticated… | |
| Pendiente de análisis | Alta (7.1) | 0.44% | 💥 PoC | Moby Go-archiveAI | 18/8/2026 | 28/8/2026 | The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a… | |
| Aplazada | Alta (8.8) | 0.62% | — | Goauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings that can contain stored credentials. The… | |
| Aplazada | Crítica (9.4) | 0.59% | — | Goauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider's signed assertion. An attacker with an account on the source… | |
| Aplazada | Media (5.3) | 0.44% | — | Goauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter used by the rest of the API. Any party able to reach the API, including an unauthenticated client, can invoke the diagnostic action… | |
| Aplazada | Alta (8.6) | 0.68% | — | Google ChromeAIGoogle Verified Access APIAIGoauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED… | |
| Aplazada | Alta (8.8) | 0.52% | — | DragonflyAI | 18/8/2026 | 10/9/2026 | Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose width times depth times sizeof(int64_t) overflows in src/core/cms.cc, allocating an undersized counter buffer while CMS.INCRBY and CMS.QUERY use the unbounded… | |
| Aplazada | Alta (7.2) | 0.33% | — | Supsystic Easy Google MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. |