Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3071▲ 536 respecto a la semana anterior
Críticas / altas1456▲ 257 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)384▲ 177 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.4)0.34%—Gnome EpiphanyAI6/8/202628/8/2026
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and…
AplazadaAlta (8)0.40%—Gnome EpiphanyAI23/1/202617/6/2026
A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused to exploit vulnerabilities within those handlers, making them appear remotely exploitable. The browser fails to properly warn or gate this action, resulting in…
AplazadaMedia (4.3)0.31%—Epiphanyit321 Referral Link TrackerAI27/10/202517/6/2026
Missing Authorization vulnerability in epiphanyit321 Referral Link Tracker referral-link-tracker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Referral Link Tracker: from n/a through <= 1.1.4.
ModificadaAlta (7.5)1.2%—Gnome EpiphanyFedoraproject Fedora20/2/202317/6/2026
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
ModificadaAlta (7.5)2.0%—Gnome EpiphanyFedoraproject FedoraDebian Linux20/4/202217/6/2026
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.
ModificadaMedia (6.1)1.4%—Gnome EpiphanyDebian Linux16/12/202117/6/2026
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
ModificadaMedia (6.1)1.5%—Gnome EpiphanyDebian Linux16/12/202117/6/2026
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.
ModificadaMedia (6.1)1.3%—Gnome EpiphanyDebian Linux16/12/202117/6/2026
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.
ModificadaMedia (6.1)1.5%—Gnome EpiphanyDebian Linux16/12/202117/6/2026
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.
ModificadaAlta (8.1)4.1%—Gnome EpiphanyWebkitgtkWpewebkit WPE WebkitFedoraproject Fedora+214/1/201917/6/2026
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
ModificadaAlta (7.5)1.1%—Epnex Epiphanycoin9/7/201817/6/2026
The mintToken function of a smart contract implementation for EpiphanyCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.9%—Gnome Epiphany7/6/201817/6/2026
libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write calls.
ModificadaAlta (7.5)1.5%—Gnome Epiphany23/5/201817/6/2026
ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.
ModificadaAlta (7.5)1.4%—Gnome Epiphany17/7/201717/6/2026
GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites.
ModificadaCrítica (9.8)1.5%—Epiphanyhealthdata Cardio Server27/12/201517/6/2026
SQL injection vulnerability in the login page in Epiphany Cardio Server 3.3 allows remote attackers to execute arbitrary SQL commands via a crafted URL.
ModificadaMedia (5.8)1.0%—Gnome Epiphany14/10/201016/6/2026
Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring, without any warning to the user, which allows man-in-the-middle attackers to spoof arbitrary https web sites via a crafted X.509 server certificate.
ModificadaMedia (6.9)0.37%—Gnome Epiphany28/1/200916/6/2026
Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
ModificadaMedia (5)1.6%—Gnome EpiphanyMozilla CaminoMozillaOmnigroup Omniweb+12/5/200516/6/2026
The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.