Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3072▲ 483 respecto a la semana anterior
Críticas / altas1456▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
16.665 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.3) | 0.29% | — | Google Chrome | 14/7/2026 | 15/7/2026 | Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.37% | — | Google Chrome | 14/7/2026 | 15/7/2026 | Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.3) | 0.27% | — | Google Chrome | 14/7/2026 | 15/7/2026 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.3) | 0.36% | — | Google Chrome | 14/7/2026 | 15/7/2026 | Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (6.5) | 0.38% | — | Google Chrome | 14/7/2026 | 15/7/2026 | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.3) | 0.29% | — | Google Chrome | 14/7/2026 | 15/7/2026 | Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (6.5) | 0.28% | — | Google Chrome | 14/7/2026 | 15/7/2026 | Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.43% | — | Google Chrome | 14/7/2026 | 15/7/2026 | Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High) | |
| Analizada | Media (6.5) | 0.40% | — | Google Chrome | 14/7/2026 | 15/7/2026 | Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (7.5) | 0.50% | — | Google Chrome | 14/7/2026 | 15/7/2026 | Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Alta (7.5) | 0.50% | — | Google Chrome | 14/7/2026 | 15/7/2026 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |
| Pendiente de análisis | Crítica (9.4) | 0.35% | — | Google Cloud BigqueryAIGoogle DataformAIGoogle Colab EnterpriseAI | 13/7/2026 | 13/7/2026 | A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository… | |
| Aplazada | Media (6.5) | 0.22% | — | Hitesh Chandwani Recaptcha FOR Asgaros ForumAIGoogle RecaptchaAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 & v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 & v3) for Asgaros Forum: from n/a through <= 1.1.0. | |
| Aplazada | Media (4.4) | 0.40% | — | Widgets FOR Google ReviewsAI | 11/7/2026 | 13/7/2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to… | |
| Aplazada | Alta (7.1) | 0.50% | — | FrappeAIGoogle ChromeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3. | |
| Pendiente de análisis | Media (5.9) | 0.30% | — | Google ApigeeAI | 9/7/2026 | 9/7/2026 | An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed. | |
| Analizada | Alta (8.8) | 0.41% | — | Google Chrome | 8/7/2026 | 10/7/2026 | Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.45% | — | Google Chrome | 8/7/2026 | 10/7/2026 | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (4.3) | 0.27% | — | Google Chrome | 8/7/2026 | 9/7/2026 | Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Media (4.3) | 0.27% | — | Google Chrome | 8/7/2026 | 9/7/2026 | Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.34% | — | Google Chrome | 8/7/2026 | 10/7/2026 | Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Media (6.1) | 0.22% | — | Google Chrome | 8/7/2026 | 9/7/2026 | Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (6.1) | 0.22% | — | Google Chrome | 8/7/2026 | 9/7/2026 | Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.41% | — | Google Chrome | 8/7/2026 | 10/7/2026 | Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.40% | — | Google Chrome | 8/7/2026 | 10/7/2026 | Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |