Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

424 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.2%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+113/4/202017/6/2026
Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
ModificadaAlta (8.8)1.8%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+113/4/202017/6/2026
Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.
ModificadaMedia (4.3)1.3%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+113/4/202017/6/2026
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.
ModificadaMedia (4.3)1.8%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+113/4/202017/6/2026
Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.
ModificadaAlta (8.8)1.6%—Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+113/4/202017/6/2026
Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (4.3)1.7%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+113/4/202017/6/2026
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+113/4/202017/6/2026
Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (4.3)1.7%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+113/4/202017/6/2026
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (4.3)1.7%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+113/4/202017/6/2026
Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (4.3)1.6%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+113/4/202017/6/2026
Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+113/4/202017/6/2026
Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+113/4/202017/6/2026
Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (7.5)2.2%—Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap+18/4/202017/6/2026
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
ModificadaAlta (7.5)1.8%—Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap8/4/202017/6/2026
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such…
ModificadaMedia (5.6)0.71%—Redhat Ansible EngineRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+431/3/202017/6/2026
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections.…
ModificadaAlta (7.5)2.9%—Gstreamer Project Gst-rtsp-serverOpensuse Backports SLEOpensuse Leap27/3/202017/6/2026
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaAlta (7.5)1.6%—OtrsOpensuse Backports SLEOpensuse LeapDebian Linux27/3/202017/6/2026
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior…
ModificadaMedia (4.3)1.3%—OtrsOpensuse Backports SLEOpensuse LeapDebian Linux27/3/202017/6/2026
Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
ModificadaMedia (4.3)1.2%—OtrsOpensuse Backports SLEOpensuse Leap27/3/202017/6/2026
In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
ModificadaCrítica (9.8)5.4%—GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap24/3/202017/6/2026
GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.
ModificadaAlta (8.8)2.7%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.3%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.3%—Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.4%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)2.9%—Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+223/3/202017/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Orbitaley — Vulnerabilidades