Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.36% | — | Okta Browser PluginAI | 23/7/2024 | 17/6/2026 | Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs when the plugin prompts the user to save these credentials within Okta Personal. A fix was implemented to properly escape these fields, addressing the vulnerability. Importantly, if… | |
| Aplazada | Crítica (9.6) | 0.37% | — | Naver Whale BrowserAI | 11/7/2024 | 17/6/2026 | Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in extension. | |
| Modificada | Media (5.9) | 0.65% | — | S3browser S3 Browser | 9/7/2024 | 17/6/2026 | An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component. | |
| Aplazada | Alta (8.2) | 0.51% | 💥 PoC | Ethz Safe Exam BrowserAI | 25/6/2024 | 17/6/2026 | Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity. By exploiting this flaw, an attacker can bypass exam controls and gain an unfair advantage during exams. | |
| Aplazada | Alta (7.6) | 0.33% | — | Hoppscotch Browser ExtensionAI | 14/5/2024 | 17/6/2026 | The Hoppscotch Browser Extension is a browser extension for Hoppscotch, a community-driven end-to-end open-source API development ecosystem. Due to an oversight during a change made to the extension in the commit d4e8e4830326f46ba17acd1307977ecd32a85b58, a critical check for the origin list was missed and allowed for… | |
| Analizada | Media (6.8) | 0.64% | — | Passbolt Browser Extension | 26/4/2024 | 17/6/2026 | An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords… | |
| Aplazada | Crítica (9.1) | 0.48% | — | Revoworks ScvxAIRevoworks BrowserAI | 1/3/2024 | 17/6/2026 | Protection mechanism failure issue exists in RevoWorks SCVX prior to scvimage4.10.21_1013 (when using 'VirusChecker' or 'ThreatChecker' feature) and RevoWorks Browser prior to 2.2.95 (when using 'VirusChecker' or 'ThreatChecker' feature). If data containing malware is saved in a specific file format (eml, dmg, vhd,… | |
| Modificada | Alta (8.8) | 0.62% | — | Minbrowser MIN | 9/2/2024 | 17/6/2026 | In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an XML document. | |
| Modificada | Alta (8.8) | 0.21% | — | Marcomilesi Browser Theme Color | 31/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Color: from n/a through 1.3. | |
| Modificada | Crítica (10) | 2.4% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity ConnectionCisco Unified Contact Center Express+1 | 26/1/2024 | 17/6/2026 | A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could… | |
| Modificada | Crítica (9.8) | 0.39% | — | Studionetworksolutions Sharebrowser | 17/1/2024 | 17/6/2026 | Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636. | |
| Modificada | Alta (7.5) | 0.53% | — | Lenovo Browser HDLenovo Browser Mobile | 3/1/2024 | 17/6/2026 | A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload that could result in the disclosure of sensitive information. | |
| Modificada | Media (6.1) | 0.46% | — | Brave Browser | 30/12/2023 | 17/6/2026 | Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_controller_factory.cc. | |
| Modificada | Crítica (9.8) | 0.76% | — | Indibrowser Indi Browser | 27/12/2023 | 17/6/2026 | An issue in Indi Browser (aka kvbrowser) v.12.11.23 allows an attacker to bypass intended access restrictions via interaction with the com.example.gurry.kvbrowswer.webview component. | |
| Modificada | Crítica (9.8) | 0.92% | — | Artistscope Artisbrowser | 27/12/2023 | 17/6/2026 | An issue in ArtistScope ArtisBrowser v.34.1.5 and before allows an attacker to bypass intended access restrictions via interaction with the com.artis.browser.IntentReceiverActivity component. NOTE: this is disputed by the vendor, who indicates that ArtisBrowser 34 does not support CSS3. | |
| Modificada | Crítica (9.8) | 1.9% | 💥 PoC | Vladymix TV Browser | 27/12/2023 | 17/6/2026 | The com.altamirano.fabricio.tvbrowser TV browser application through 4.5.1 for Android is vulnerable to JavaScript code execution via an explicit intent due to an exposed MainActivity. | |
| Modificada | Crítica (9.8) | 1.1% | 💥 PoC | TCL Browser TV WEB - Browsehere | 27/12/2023 | 17/6/2026 | An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote attacker to execute arbitrary JavaScript code via the com.tcl.browser.portal.browse.activity.BrowsePageActivity component. | |
| Modificada | Alta (7.5) | 1.3% | — | Buddho Etcd Browser | 7/12/2023 | 17/6/2026 | An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying a /../../../ Directory Traversal input to the URL's GET request while connecting to the remote server port specified during setup, an attacker can retrieve local operating system files from the remote system. | |
| Modificada | Media (5.5) | 0.23% | — | Naver Whale Browser | 27/11/2023 | 17/6/2026 | The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature. | |
| Modificada | Baja (3.7) | 0.49% | — | Cjvnjde Google Translate API Browser | 24/11/2023 | 17/6/2026 | google-translate-api-browser is an npm package which interfaces with the google translate web api. A Server-Side Request Forgery (SSRF) Vulnerability is present in applications utilizing the `google-translate-api-browser` package and exposing the `translateOptions` to the end user. An attacker can set a malicious… | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Alta (8.8) | 0.31% | — | WP Browserupdate | 10/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.4.1 versions. | |
| Analizada | Alta (7.5) | 0.51% | — | Browserify-signDebian Linux | 26/10/2023 | 17/6/2026 | browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on indutny/tls.js. An upper bound check issue in `dsaVerify` function allows an attacker to construct signatures that can be successfully verified by any public key, thus… | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens Xpedition Layout Browser | 10/10/2023 | 17/6/2026 | A vulnerability has been identified in Xpedition Layout Browser (All versions < VX.2.14). Affected application contains a stack overflow vulnerability when parsing a PCB file. An attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Media (6.1) | 0.41% | — | Palantir Gotham-fe-bundlePalantir Titanium-browser-app-bundle | 27/9/2023 | 17/6/2026 | Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to a newly created property or link. |