Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
4720 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.22% | — | Apple IpadosApple Iphone OS | 17/8/2026 | 25/8/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Aplazada | Alta (7.5) | 0.21% | — | Integrate Phonepe With WoocommerceAI | 6/8/2026 | 26/8/2026 | The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark… | |
| Aplazada | Crítica (9.1) | 0.42% | — | OTP Login With Phone NumberAI | 5/8/2026 | 26/8/2026 | The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can… | |
| Analizada | Alta (8.8) | 0.43% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 27/7/2026 | 28/7/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Analizada | Crítica (9.8) | 0.66% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 29/7/2026 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination. | |
| Modificada | Crítica (9.8) | 0.80% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap… | |
| Modificada | Crítica (9.8) | 0.78% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. | |
| Modificada | Crítica (9.8) | 0.85% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. | |
| Modificada | Crítica (9.8) | 0.80% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or… | |
| Modificada | Crítica (9.8) | 0.80% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or… | |
| Modificada | Alta (8.1) | 0.57% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may cause an unexpected app termination. | |
| Modificada | Alta (7.8) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 17/8/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app… | |
| Modificada | Alta (7.8) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 17/8/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app… | |
| Modificada | Alta (7.8) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 17/8/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected… | |
| Modificada | Alta (7.8) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 17/8/2026 | An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected… | |
| Analizada | Alta (7.8) | 0.17% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 28/7/2026 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination. | |
| Modificada | Alta (8.8) | 0.47% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 27/7/2026 | 17/8/2026 | A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (5.5) | 0.17% | — | Apple IpadosApple Iphone OS | 27/7/2026 | 17/8/2026 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6. An app may be able to access sensitive user data. | |
| Analizada | Media (5.5) | 0.16% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 29/7/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to a denial-of-service. | |
| Analizada | Crítica (9.8) | 0.59% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 28/7/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory. | |
| Modificada | Alta (7.8) | 0.17% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 27/7/2026 | 17/8/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory. | |
| Modificada | Alta (7.8) | 0.19% | 💥 PoC | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 17/8/2026 | A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to execute arbitrary code with kernel privileges. | |
| Modificada | Crítica (9.8) | 0.56% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 27/7/2026 | 17/8/2026 | An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization. | |
| Modificada | Media (6.5) | 0.41% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 17/8/2026 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data. | |
| Modificada | Media (6.5) | 0.26% | — | Apple IpadosApple Iphone OSApple TvosApple Visionos+1 | 27/7/2026 | 17/8/2026 | This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data. |