Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
3303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap+1 | 21/9/2020 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension. | |
| Modificada | Alta (8.8) | 2.9% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.9% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Crítica (9.6) | 1.5% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | |
| Modificada | Crítica (9.6) | 1.5% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.2% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering. | |
| Modificada | Alta (7.8) | 0.71% | — | Nodejs Node.jsOpensuse LeapFedoraproject Fedora | 18/9/2020 | 17/6/2026 | The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes. | |
| Modificada | Alta (7.4) | 5.3% | — | Nodejs Node.jsOpensuse LeapFedoraproject Fedora | 18/9/2020 | 17/6/2026 | Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying… | |
| Modificada | Alta (7.8) | 0.22% | — | Google AndroidOpensuse Leap | 17/9/2020 | 17/6/2026 | In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-143560807 | |
| Modificada | Media (6.7) | 0.22% | — | Google AndroidOpensuse Leap | 17/9/2020 | 17/6/2026 | In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-144161459 | |
| Modificada | Media (5.5) | 0.49% | — | Google AndroidDebian LinuxOpensuse LeapStarwindsoftware Starwind Virtual SAN | 17/9/2020 | 17/6/2026 | In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171 | |
| Modificada | Media (4.7) | 0.49% | — | Perl DBIFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+1 | 17/9/2020 | 17/6/2026 | An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference. | |
| Modificada | Alta (8.8) | 2.0% | — | Sylabs SingularityOpensuse Leap | 16/9/2020 | 17/6/2026 | Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039. | |
| Modificada | Alta (8.1) | 2.0% | — | Sylabs SingularityOpensuse Leap | 16/9/2020 | 17/6/2026 | Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution. | |
| Modificada | Alta (7.1) | 0.61% | — | Perl Database InterfaceOpensuse LeapDebian LinuxFedoraproject Fedora | 16/9/2020 | 17/6/2026 | A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data. | |
| Modificada | Media (5.5) | 0.55% | — | Perl Database InterfaceCanonical Ubuntu LinuxOpensuse LeapFedoraproject Fedora+1 | 16/9/2020 | 17/6/2026 | An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability. | |
| Modificada | Alta (7.8) | 1.3% | 💥 PoC | Linux KernelDebian LinuxFedoraproject FedoraOpensuse Leap | 16/9/2020 | 17/6/2026 | A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity. | |
| Modificada | Media (6.5) | 3.2% | — | Google BrotliDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+6 | 15/9/2020 | 17/6/2026 | A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or… | |
| Modificada | Media (4.1) | 0.31% | — | Linux KernelDebian LinuxOpensuse Leap | 13/9/2020 | 17/6/2026 | The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe. | |
| Modificada | Alta (7.5) | 2.2% | — | Atftp Project AtftpDebian LinuxOpensuse Leap | 10/9/2020 | 17/6/2026 | An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 4.4% | — | Libproxy Project LibproxyDebian LinuxFedoraproject FedoraOpensuse Leap+1 | 9/9/2020 | 17/6/2026 | url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion. | |
| Modificada | Alta (7) | 0.27% | — | Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux | 9/9/2020 | 17/6/2026 | A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452. | |
| Modificada | Alta (7) | 0.65% | — | Samba Cifs-utilsFedoraproject FedoraOpensuse Leap | 9/9/2020 | 17/6/2026 | It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges. |