Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
–

419 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.29%—WebkitgtkAI31/8/202630/9/2026
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
Pendiente de análisisAlta (8.8)0.29%—WebkitgtkAI24/8/202630/9/2026
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.
AplazadaMedia (6.1)0.95%—Perl PDF WebkitAI13/8/202626/8/2026
PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for. to_pdf reads the generated PDF back from its path argument, and _style_tag_for reads each entry of the stylesheets list, by assigning the path to a local @ARGV…
AplazadaCrítica (9.8)0.73%—PDF WebkitAI13/8/202626/8/2026
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every <meta name="pdf-webkit-KEY" content="VALUE"> element in the document head through _pdf_webkit_meta_tags and turns each one into a…
AplazadaAlta (8.5)0.36%—Inet WebkitAI2/7/20262/7/2026
Contributor SQL Injection in iNET Webkit 1.2.4 versions.
Pendiente de análisisMedia (4.7)0.23%—WebkitgtkAIWPE WebkitAI23/4/202617/6/2026
An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal…
AplazadaMedia (6.5)0.39%—Inet WebkitAI23/1/202617/6/2026
Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iNET Webkit: from n/a through <= 1.2.4.
AnalizadaCrítica (9.3)0.59%—Welltend Bpmflowwebkit29/12/202517/6/2026
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AnalizadaAlta (8.7)0.54%—Welltend Bpmflowwebkit29/12/202517/6/2026
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
AplazadaAlta (8.8)0.47%—WebkitgtkAI4/12/202525/9/2026
A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
AplazadaAlta (7.4)0.33%—WebkitgtkAI3/12/202525/9/2026
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
AplazadaAlta (7.5)0.58%—WebkitgtkAIWPE WebkitAI25/11/202529/6/2026
A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.
AplazadaAlta (7.5)0.46%—LibsoupAIGnomeAIWebkitAI23/10/202530/6/2026
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state…
ModificadaCrítica (9.8)0.78%—Apple SafariApple IpadosApple Iphone OSApple Macos+515/9/202517/6/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
ModificadaCrítica (9.8)0.75%—Apple SafariApple IpadosApple Iphone OSApple Macos+515/9/202517/6/2026
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
AnalizadaAlta (8.8)1.6%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+1129/7/202521/9/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
AnalizadaAlta (8.8)9.6%⚠ Explotación activaGoogle ChromeDebian LinuxApple SafariApple Ipados+615/7/20251/10/2026
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
AplazadaMedia (5.3)0.29%—Inet WebkitAI27/3/202517/6/2026
Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iNET Webkit: from n/a through <= 1.2.2.
ModificadaMedia (5.5)0.60%—Apple SafariApple IpadosApple Iphone OSApple Macos+514/5/202417/6/2026
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
ModificadaMedia (6.5)1.5%—Apple SafariApple IpadosApple Iphone OSApple Macos+68/3/202417/6/2026
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
ModificadaMedia (6.5)1.3%—Apple SafariApple Ipad OSApple Iphone OSApple Macos+58/3/202417/6/2026
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
ModificadaMedia (6.5)1.5%—Apple SafariApple IpadosApple Iphone OSApple Macos+68/3/202417/6/2026
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
ModificadaMedia (6.5)1.3%—Apple SafariApple Ipad OSApple Iphone OSApple Macos+68/3/202417/6/2026
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
AnalizadaMedia (4.3)0.85%—Apple SafariApple Ipad OSApple Iphone OSApple Macos+321/2/202417/6/2026
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
AnalizadaAlta (8.8)9.3%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+330/11/202317/6/2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before…