Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+1 | 13/4/2020 | 17/6/2026 | Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension. | |
| Modificada | Alta (8.8) | 1.8% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+1 | 13/4/2020 | 17/6/2026 | Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.3% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. | |
| Modificada | Media (4.3) | 1.8% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+1 | 13/4/2020 | 17/6/2026 | Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application. | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.7% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+1 | 13/4/2020 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.7% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+1 | 13/4/2020 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.7% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+1 | 13/4/2020 | 17/6/2026 | Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.6% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+1 | 13/4/2020 | 17/6/2026 | Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+1 | 13/4/2020 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+1 | 13/4/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (7.5) | 2.2% | — | Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap+1 | 8/4/2020 | 17/6/2026 | An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss. | |
| Modificada | Alta (7.5) | 1.8% | — | Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap | 8/4/2020 | 17/6/2026 | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such… | |
| Modificada | Media (5.6) | 0.71% | — | Redhat Ansible EngineRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+4 | 31/3/2020 | 17/6/2026 | A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections.… | |
| Modificada | Alta (7.5) | 2.9% | — | Gstreamer Project Gst-rtsp-serverOpensuse Backports SLEOpensuse Leap | 27/3/2020 | 17/6/2026 | An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.6% | — | OtrsOpensuse Backports SLEOpensuse LeapDebian Linux | 27/3/2020 | 17/6/2026 | It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior… | |
| Modificada | Media (4.3) | 1.3% | — | OtrsOpensuse Backports SLEOpensuse LeapDebian Linux | 27/3/2020 | 17/6/2026 | Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions. | |
| Modificada | Media (4.3) | 1.2% | — | OtrsOpensuse Backports SLEOpensuse Leap | 27/3/2020 | 17/6/2026 | In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions. | |
| Modificada | Crítica (9.8) | 5.4% | — | GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap | 24/3/2020 | 17/6/2026 | GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c. | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.4% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.9% | — | Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 23/3/2020 | 17/6/2026 | Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |