Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.29% | — | WebkitgtkAI | 31/8/2026 | 30/9/2026 | A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. | |
| Pendiente de análisis | Alta (8.8) | 0.29% | — | WebkitgtkAI | 24/8/2026 | 30/9/2026 | A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption. | |
| Aplazada | Media (6.1) | 0.95% | — | Perl PDF WebkitAI | 13/8/2026 | 26/8/2026 | PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for. to_pdf reads the generated PDF back from its path argument, and _style_tag_for reads each entry of the stylesheets list, by assigning the path to a local @ARGV… | |
| Aplazada | Crítica (9.8) | 0.73% | — | PDF WebkitAI | 13/8/2026 | 26/8/2026 | PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every <meta name="pdf-webkit-KEY" content="VALUE"> element in the document head through _pdf_webkit_meta_tags and turns each one into a… | |
| Aplazada | Alta (8.5) | 0.36% | — | Inet WebkitAI | 2/7/2026 | 2/7/2026 | Contributor SQL Injection in iNET Webkit 1.2.4 versions. | |
| Pendiente de análisis | Media (4.7) | 0.23% | — | WebkitgtkAIWPE WebkitAI | 23/4/2026 | 17/6/2026 | An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal… | |
| Aplazada | Media (6.5) | 0.39% | — | Inet WebkitAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iNET Webkit: from n/a through <= 1.2.4. | |
| Analizada | Crítica (9.3) | 0.59% | — | Welltend Bpmflowwebkit | 29/12/2025 | 17/6/2026 | BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analizada | Alta (8.7) | 0.54% | — | Welltend Bpmflowwebkit | 29/12/2025 | 17/6/2026 | BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files. | |
| Aplazada | Alta (8.8) | 0.47% | — | WebkitgtkAI | 4/12/2025 | 25/9/2026 | A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling. | |
| Aplazada | Alta (7.4) | 0.33% | — | WebkitgtkAI | 3/12/2025 | 25/9/2026 | A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser. | |
| Aplazada | Alta (7.5) | 0.58% | — | WebkitgtkAIWPE WebkitAI | 25/11/2025 | 29/6/2026 | A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server. | |
| Aplazada | Alta (7.5) | 0.46% | — | LibsoupAIGnomeAIWebkitAI | 23/10/2025 | 30/6/2026 | A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state… | |
| Modificada | Crítica (9.8) | 0.78% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+5 | 15/9/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Crítica (9.8) | 0.75% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+5 | 15/9/2025 | 17/6/2026 | A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos+11 | 29/7/2025 | 21/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Analizada | Alta (8.8) | 9.6% | ⚠ Explotación activa | Google ChromeDebian LinuxApple SafariApple Ipados+6 | 15/7/2025 | 1/10/2026 | Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Aplazada | Media (5.3) | 0.29% | — | Inet WebkitAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iNET Webkit: from n/a through <= 1.2.2. | |
| Modificada | Media (5.5) | 0.60% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+5 | 14/5/2024 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. | |
| Modificada | Media (6.5) | 1.5% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+6 | 8/3/2024 | 17/6/2026 | A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. | |
| Modificada | Media (6.5) | 1.3% | — | Apple SafariApple Ipad OSApple Iphone OSApple Macos+5 | 8/3/2024 | 17/6/2026 | An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user. | |
| Modificada | Media (6.5) | 1.5% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+6 | 8/3/2024 | 17/6/2026 | A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. | |
| Modificada | Media (6.5) | 1.3% | — | Apple SafariApple Ipad OSApple Iphone OSApple Macos+6 | 8/3/2024 | 17/6/2026 | The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin. | |
| Analizada | Media (4.3) | 0.85% | — | Apple SafariApple Ipad OSApple Iphone OSApple Macos+3 | 21/2/2024 | 17/6/2026 | An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing. | |
| Analizada | Alta (8.8) | 9.3% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/11/2023 | 17/6/2026 | A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before… |