Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

58 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.3%—Icinga WEB 2Debian LinuxSuse Package HUB19/8/202017/6/2026
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.
ModificadaMedia (5.4)1.4%—PhpmyadminDebian LinuxFedoraproject FedoraOpensuse Backports SLE+222/3/202017/6/2026
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into…
ModificadaAlta (8)1.8%—PhpmyadminDebian LinuxFedoraproject FedoraOpensuse Backports SLE+222/3/202017/6/2026
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or…
ModificadaAlta (8)2.4%—PhpmyadminFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+122/3/202017/6/2026
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim…
ModificadaAlta (8.8)74%—CactiFedoraproject FedoraOpmantek Open-auditOpensuse Suse Package HUB+122/2/202017/6/2026
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
ModificadaAlta (8.8)2.0%—Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+411/2/202017/6/2026
Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.0%—Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+411/2/202017/6/2026
Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.6%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.
ModificadaAlta (8.8)1.8%—Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+311/2/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.0%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (4.3)1.6%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaAlta (8.8)2.7%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
ModificadaMedia (6.5)2.0%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (8.8)1.8%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaMedia (6.5)1.9%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
ModificadaMedia (4.3)1.7%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaMedia (5.4)1.7%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
ModificadaMedia (6.5)1.9%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaMedia (4.3)1.5%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
ModificadaMedia (4.3)1.3%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.
ModificadaAlta (8.8)3.1%—Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+411/2/202017/6/2026
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.3%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.
ModificadaAlta (8.8)2.3%—Google ChromeFedoraproject FedoraDebian LinuxSuse Package HUB+411/2/202017/6/2026
Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.2%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux+411/2/202017/6/2026
Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (5.3)1.9%—Nextcloud ServerOpensuse Backports SLESuse Package HUB4/2/202017/6/2026
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.