Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.4% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.9% | — | Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 23/3/2020 | 17/6/2026 | Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 3.5% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.4% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (7.5) | 2.3% | — | Torproject TOROpensuse Backports SLEOpensuse Leap | 23/3/2020 | 17/6/2026 | Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negotiated twice on the same circuit. | |
| Modificada | Media (5.4) | 1.4% | — | PhpmyadminDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 22/3/2020 | 17/6/2026 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into… | |
| Modificada | Alta (8) | 1.8% | — | PhpmyadminDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 22/3/2020 | 17/6/2026 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or… | |
| Modificada | Alta (8) | 2.4% | — | PhpmyadminFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+1 | 22/3/2020 | 17/6/2026 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim… | |
| Modificada | Media (6.5) | 8.0% | — | GraphicsmagickDebian LinuxOpensuse Backports SLEOpensuse Leap | 18/3/2020 | 17/6/2026 | In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG. | |
| Modificada | Alta (7) | 0.68% | — | NagiosOpensuse Backports SLEOpensuse Leap | 28/2/2020 | 17/6/2026 | UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server… | |
| Modificada | Crítica (9.1) | 2.8% | — | Openfortivpn Project OpenfortivpnFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 27/2/2020 | 17/6/2026 | An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack. | |
| Modificada | Media (5.3) | 1.6% | — | Openfortivpn Project OpenfortivpnFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 27/2/2020 | 17/6/2026 | An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted). | |
| Modificada | Media (5.3) | 1.7% | — | Openfortivpn Project OpenfortivpnFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 27/2/2020 | 17/6/2026 | An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value. | |
| Modificada | Alta (8.8) | 12% | 💥 PoC | ProftpdDebian LinuxFedoraproject FedoraOpensuse Backports SLE+3 | 20/2/2020 | 17/6/2026 | In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution. | |
| Modificada | Alta (7.5) | 2.1% | — | ProftpdSiemens Simatic NET CP 1543-1 FirmwareSiemens Simatic NET CP 1545-1 FirmwareOpensuse Backports SLE+1 | 20/2/2020 | 17/6/2026 | ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function. | |
| Modificada | Crítica (9.8) | 3.7% | — | WeechatFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+1 | 12/2/2020 | 17/6/2026 | irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode). | |
| Modificada | Alta (8.8) | 2.0% | — | Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+4 | 11/2/2020 | 17/6/2026 | Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.0% | — | Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+4 | 11/2/2020 | 17/6/2026 | Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeOpensuse Backports SLE | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeOpensuse Backports SLE | 11/2/2020 | 17/6/2026 | Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators via a crafted HTML page. | |
| Modificada | Media (5.4) | 1.5% | — | Google ChromeOpensuse Backports SLE | 11/2/2020 | 17/6/2026 | Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. | |
| Modificada | Media (6.5) | 1.6% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.0% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.6% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+4 | 11/2/2020 | 17/6/2026 | Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. |