Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1338▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.4) | 0.21% | — | Paloaltonetworks Idira Identity Browser Extension | 11/6/2026 | 22/6/2026 | Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger… | |
| Aplazada | Media (5.1) | 0.26% | — | Deepl Chrome Browser ExtensionAI | 22/4/2026 | 17/6/2026 | DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in a user's browser, and inject malicious HTML into web pages viewed by the user. | |
| Pendiente de análisis | Media (6) | 0.26% | — | Pega Browser ExtensionAIPega Robotic AutomationAI | 7/4/2026 | 17/6/2026 | A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension. A bad actor could create a website that contains malicious code that targets PBE. The vulnerability could occur if a user navigates to this website.… | |
| Pendiente de análisis | Alta (7.2) | 0.32% | — | Pega Browser ExtensionAIPega Robotic AutomationAI | 7/4/2026 | 17/6/2026 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge. A bad actor could create a website that includes malicious code. The vulnerability could occur if a Robot Runtime… | |
| Pendiente de análisis | Crítica (9) | 0.32% | — | Pega Browser ExtensionAIPega Robot StudioAI | 23/3/2026 | 17/6/2026 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25. This vulnerability does not affect Robot Runtime users. A bad actor could create a website that includes malicious code. The… | |
| Aplazada | Alta (7.6) | 0.33% | — | Hoppscotch Browser ExtensionAI | 14/5/2024 | 17/6/2026 | The Hoppscotch Browser Extension is a browser extension for Hoppscotch, a community-driven end-to-end open-source API development ecosystem. Due to an oversight during a change made to the extension in the commit d4e8e4830326f46ba17acd1307977ecd32a85b58, a critical check for the origin list was missed and allowed for… | |
| Analizada | Media (6.8) | 0.64% | — | Passbolt Browser Extension | 26/4/2024 | 17/6/2026 | An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords… | |
| Modificada | Media (5.9) | 1.0% | — | Trustwallet Trust Wallet Browser ExtensionTrustwallet Trust Wallet Core | 27/4/2023 | 17/6/2026 | Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the entropy is 32 bits, as exploited in the wild in December 2022 and March 2023. This occurs because the mt19937 Mersenne Twister takes a single 32-bit value as an input seed, resulting in only… |