Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
522 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.0% | — | Apple SafariApple Iphone OSWebkitgtk | 18/12/2019 | 17/6/2026 | A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting. | |
| Modificada | Media (6.1) | 1.2% | — | Apple IcloudApple ItunesWebkitgtk+ | 18/12/2019 | 17/6/2026 | A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting. | |
| Modificada | Alta (8.8) | 1.4% | — | Webkul Bagisto | 18/9/2019 | 17/6/2026 | In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers. | |
| Modificada | Alta (8.8) | 0.60% | — | Webkul Bagisto | 11/8/2019 | 17/6/2026 | Bagisto 0.1.5 allows CSRF under /admin URIs. | |
| Modificada | Media (5.3) | 3.3% | — | WebkitgtkWpewebkit WPE Webkit | 10/4/2019 | 17/6/2026 | WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded. | |
| Modificada | Alta (8.8) | 1.8% | — | Apple SafariApple Iphone OSApple TvosApple Icloud+2 | 5/3/2019 | 17/6/2026 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | WebkitgtkWebkitgtk+Opensuse LeapCanonical Ubuntu Linux | 24/2/2019 | 17/6/2026 | The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact,… | |
| Modificada | Alta (8.1) | 4.3% | — | Gnome EpiphanyWebkitgtkWpewebkit WPE WebkitFedoraproject Fedora+2 | 14/1/2019 | 17/6/2026 | WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge. | |
| Modificada | Alta (8.8) | 2.0% | — | Apple SafariApple Iphone OSApple TvosApple Watchos+4 | 11/1/2019 | 17/6/2026 | In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. | |
| Modificada | Alta (8.8) | 2.1% | — | Apple SafariApple Iphone OSApple TvosApple Watchos+4 | 11/1/2019 | 17/6/2026 | In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. | |
| Modificada | Alta (8.8) | 2.2% | — | Apple SafariApple Iphone OSApple TvosApple Watchos+3 | 11/1/2019 | 17/6/2026 | In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks. | |
| Modificada | Alta (8.8) | 2.1% | — | Apple SafariApple Iphone OSApple TvosApple Watchos+4 | 11/1/2019 | 17/6/2026 | In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. | |
| Modificada | Alta (8.8) | 2.1% | — | Apple SafariApple Iphone OSApple TvosApple Watchos+4 | 11/1/2019 | 17/6/2026 | In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. | |
| Modificada | Alta (8.8) | 2.0% | — | Apple SafariApple Iphone OSApple TvosApple Watchos+4 | 11/1/2019 | 17/6/2026 | In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks. | |
| Modificada | Crítica (9.8) | 1.7% | — | Webkitgtk+Canonical Ubuntu Linux | 19/7/2018 | 17/6/2026 | WebKitGTK+ 2.20.3 has an off-by-one error, with a resultant out-of-bounds write, in the get_simple_globs functions in ThirdParty/xdgmime/src/xdgmimecache.c and ThirdParty/xdgmime/src/xdgmimeglob.c. | |
| Modificada | Alta (8.8) | 2.4% | — | Webkitgtk+ | 19/6/2018 | 17/6/2026 | WebCore/platform/graphics/texmap/TextureMapperLayer.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.2, is vulnerable to a use after free for a WebCore::TextureMapperLayer object. | |
| Modificada | Alta (8.8) | 10% | 💥 Exploit | Canonical Ubuntu LinuxWebkitgtk+Wpewebkit WPE Webkit | 19/6/2018 | 17/6/2026 | The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by… | |
| Modificada | Media (6.5) | 1.6% | — | Webkitgtk+Gnome Libsoup | 4/6/2018 | 17/6/2026 | WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a… | |
| Modificada | Alta (7.5) | 1.2% | — | Webkitgtk+ | 4/6/2018 | 17/6/2026 | WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections. | |
| Modificada | Alta (8.1) | 1.7% | — | Nodewebkit Project Nodewebkit | 1/6/2018 | 17/6/2026 | nodewebkit is an installer for node-webkit. nodewebkit downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled zip file if the attacker is on the network or positioned in… | |
| Modificada | Alta (7.5) | 69% | 💥 Exploit | Webkitgtk+ | 1/6/2018 | 17/6/2026 | webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3, mishandle an unset pageURL, leading to an application crash. | |
| Modificada | Alta (8.8) | 1.9% | — | Apple SafariApple Iphone OSApple TvosApple Icloud+3 | 3/4/2018 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary… | |
| Modificada | Alta (8.8) | 2.0% | — | Apple SafariApple Iphone OSApple TvosApple Watchos+4 | 3/4/2018 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows… | |
| Modificada | Alta (8.8) | 38% | 💥 Exploit | Apple SafariApple Iphone OSApple TvosApple Watchos+4 | 3/4/2018 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows… | |
| Modificada | Media (6.5) | 1.3% | — | Apple SafariApple Iphone OSApple TvosApple Watchos+4 | 3/4/2018 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows… |