Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3077▲ 447 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
16.665 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 0.34% | — | Google Chrome | 30/7/2026 | 6/8/2026 | Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Crítica (9.6) | 0.55% | — | Google Chrome | 30/7/2026 | 6/8/2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Alta (7.8) | 0.10% | — | Google Chrome | 30/7/2026 | 6/8/2026 | Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical) | |
| Analizada | Alta (8.3) | 0.49% | — | Google Chrome | 30/7/2026 | 6/8/2026 | Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Crítica (9.6) | 0.34% | — | Google Chrome | 30/7/2026 | 6/8/2026 | Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Crítica (9.6) | 0.34% | — | Google Chrome | 30/7/2026 | 3/8/2026 | Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Alta (8.3) | 0.30% | — | Google Chrome | 30/7/2026 | 6/8/2026 | Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Media (5.3) | 0.27% | — | Google Chrome | 29/7/2026 | 21/9/2026 | Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via malicious network traffic. (Chromium security severity: Low) | |
| Analizada | Crítica (9.6) | 0.34% | — | Google Chrome | 29/7/2026 | 24/9/2026 | Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.47% | — | Google Chrome | 29/7/2026 | 24/9/2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Aplazada | Alta (8.3) | 0.67% | — | Google IMS ServiceAI | 28/7/2026 | 30/7/2026 | Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code. | |
| Analizada | Media (6) | 0.19% | — | Google MCP Toolbox FOR Databases | 27/7/2026 | 28/9/2026 | A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport… | |
| Aplazada | Media (4.3) | 0.14% | — | Ljapps WP Google Review SliderAI | 27/7/2026 | 27/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | Ljapps WP Google Review SliderAI | 27/7/2026 | 27/7/2026 | Administrator SQL Injection in WP Google Review Slider <= 18.4 versions. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Image WebpAIGoogle LibwebpAI | 24/7/2026 | 31/7/2026 | Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP… | |
| Pendiente de análisis | Alta (8.7) | 0.45% | — | Google Cloud LookerAI | 24/7/2026 | 27/7/2026 | A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to administrative account takeover using a maliciously crafted… | |
| Aplazada | Media (6.4) | 0.42% | — | Rich Showcase FOR Google ReviewsAI | 24/7/2026 | 24/7/2026 | The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Analizada | Alta (8.8) | 0.34% | — | Google Chrome | 23/7/2026 | 27/7/2026 | Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.52% | — | Google Chrome | 23/7/2026 | 27/7/2026 | Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.41% | — | Google Chrome | 23/7/2026 | 27/7/2026 | Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.3) | 0.30% | — | Google Chrome | 23/7/2026 | 27/7/2026 | Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Aplazada | Alta (7.1) | 0.25% | — | WP Google Maps PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. | |
| Pendiente de análisis | Baja (3.3) | 0.13% | — | Ansible LightspeedAIMicrosoft Visual Studio CodeAIGoogle GeminiAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's… | |
| Analizada | Crítica (9.6) | 0.34% | — | Google Chrome | 21/7/2026 | 24/7/2026 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.34% | — | Google Chrome | 21/7/2026 | 24/7/2026 | Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |