Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2748▲ 37 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.29%—WebkitgtkAI31/8/202630/9/2026
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
Pendiente de análisisAlta (8.8)0.29%—WebkitgtkAI24/8/202630/9/2026
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.
Pendiente de análisisMedia (4.7)0.23%—WebkitgtkAIWPE WebkitAI23/4/202617/6/2026
An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal…
AplazadaAlta (8.8)0.47%—WebkitgtkAI4/12/202525/9/2026
A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
AplazadaAlta (7.4)0.33%—WebkitgtkAI3/12/202525/9/2026
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
AplazadaAlta (7.5)0.58%—WebkitgtkAIWPE WebkitAI25/11/202529/6/2026
A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.
ModificadaCrítica (9.8)0.78%—Apple SafariApple IpadosApple Iphone OSApple Macos+515/9/202517/6/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
ModificadaCrítica (9.8)0.75%—Apple SafariApple IpadosApple Iphone OSApple Macos+515/9/202517/6/2026
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
AnalizadaAlta (8.8)1.6%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+1129/7/202521/9/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
AnalizadaAlta (8.8)9.6%⚠ Explotación activaGoogle ChromeDebian LinuxApple SafariApple Ipados+615/7/20251/10/2026
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (5.5)0.60%—Apple SafariApple IpadosApple Iphone OSApple Macos+514/5/202417/6/2026
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
ModificadaMedia (6.5)1.5%—Apple SafariApple IpadosApple Iphone OSApple Macos+68/3/202417/6/2026
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
ModificadaMedia (6.5)1.3%—Apple SafariApple Ipad OSApple Iphone OSApple Macos+58/3/202417/6/2026
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
ModificadaMedia (6.5)1.5%—Apple SafariApple IpadosApple Iphone OSApple Macos+68/3/202417/6/2026
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
ModificadaMedia (6.5)1.3%—Apple SafariApple Ipad OSApple Iphone OSApple Macos+68/3/202417/6/2026
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
AnalizadaMedia (4.3)0.85%—Apple SafariApple Ipad OSApple Iphone OSApple Macos+321/2/202417/6/2026
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
AnalizadaAlta (8.8)9.3%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+330/11/202317/6/2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before…
AnalizadaMedia (6.5)18%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+330/11/202317/6/2026
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS…
ModificadaAlta (8.8)1.4%—WebkitgtkDebian LinuxFedoraproject Fedora6/10/202317/6/2026
A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.
AnalizadaAlta (8.8)24%⚠ Explotación activaApple IpadosApple Iphone OSApple MacosFedoraproject Fedora+1021/9/202317/6/2026
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
ModificadaCrítica (9.8)1.7%—Apple MacosWebkitgtkWpewebkit WPE Webkit6/9/202317/6/2026
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.
ModificadaMedia (5.3)0.79%—Apple MacosWebkitgtkWpewebkit WPE Webkit6/9/202317/6/2026
A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. Content Security Policy to block domains with wildcards may fail.
ModificadaAlta (8.8)0.93%—Apple IpadosApple Iphone OSApple MacosWebkitgtk+114/8/202317/6/2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.
AnalizadaAlta (8.8)19%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+327/7/202317/6/2026
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
AnalizadaAlta (8.8)24%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+123/6/202317/6/2026
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been…