Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1671 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.4% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 27/1/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing web content may lead to a denial-of-service. | |
| Modificada | Alta (8.8) | 3.0% | — | Apple SafariApple IpadosApple Iphone OSApple Macos | 27/1/2025 | 17/6/2026 | A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command injection. | |
| Modificada | Media (6.5) | 0.83% | — | Apple SafariApple IpadosApple MacosApple Visionos | 27/1/2025 | 17/6/2026 | The issue was addressed with improved access restrictions to the file system. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user. | |
| Modificada | Media (4.3) | 0.58% | — | Apple SafariApple IpadosApple Iphone OSApple Macos | 27/1/2025 | 17/6/2026 | The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Visiting a malicious website may lead to address bar spoofing. | |
| Modificada | Media (4.3) | 0.80% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 27/1/2025 | 17/6/2026 | The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, watchOS 11.4. Visiting a malicious website may lead to user interface spoofing. | |
| Modificada | Alta (8.8) | 0.81% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 27/1/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Crítica (9.1) | 0.70% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 27/1/2025 | 17/6/2026 | An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, watchOS 11.2. Private Browsing tabs may be accessed without authentication. | |
| Modificada | Alta (7.8) | 0.62% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 15/1/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a file may lead to unexpected app termination or arbitrary code execution. | |
| Modificada | Crítica (9.8) | 1.0% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/12/2024 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Alta (7.5) | 0.97% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/12/2024 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Alta (8.8) | 1.1% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/12/2024 | 17/6/2026 | A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption. | |
| Modificada | Media (6.5) | 17% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/12/2024 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Alta (7.5) | 1.6% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 12/12/2024 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (5.3) | 1.1% | — | Apple SafariApple IpadosApple Iphone OSApple Macos | 12/12/2024 | 17/6/2026 | The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website. | |
| Modificada | Media (5.3) | 0.26% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 12/12/2024 | 17/6/2026 | A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin. | |
| Analizada | Media (6.3) | 23% | ⚠ Explotación activa | Debian LinuxApple SafariApple IpadosApple Iphone OS+2 | 20/11/2024 | 17/6/2026 | A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a… | |
| Analizada | Alta (8.8) | 10% | ⚠ Explotación activa💥 PoC | Debian LinuxApple SafariApple IpadosApple Iphone OS+2 | 20/11/2024 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been… | |
| Modificada | Media (5.4) | 0.66% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 28/10/2024 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. | |
| Modificada | Alta (7.5) | 1.0% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 28/10/2024 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1. An attacker may be able to misuse a trust relationship to download malicious content. | |
| Modificada | Media (4.3) | 0.96% | — | Apple IpadosApple Iphone OSApple MacosApple Safari+3 | 28/10/2024 | 17/6/2026 | A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (6.5) | 0.56% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 28/10/2024 | 17/6/2026 | A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, watchOS 11. Maliciously crafted web content may violate iframe sandboxing policy. | |
| Modificada | Crítica (9.3) | 0.46% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 24/10/2024 | 17/6/2026 | An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. A user may be able to bypass some web content restrictions. | |
| Modificada | Media (5.5) | 0.29% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 24/10/2024 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Media (6.5) | 0.65% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 17/9/2024 | 17/6/2026 | A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin. | |
| Modificada | Media (6.5) | 0.93% | — | Apple SafariApple Macos | 17/9/2024 | 17/6/2026 | The issue was addressed with improved UI. This issue is fixed in Safari 18, macOS Sequoia 15. Visiting a malicious website may lead to address bar spoofing. |