Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3979 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 8/7/2025 | 17/6/2026 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (5.2) | 0.15% | — | Docker DesktopAI | 3/7/2025 | 17/6/2026 | System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain secrets and further use them to gain… | |
| Modificada | Media (5.5) | 0.45% | — | Freedesktop Poppler | 2/7/2025 | 17/6/2026 | Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue. | |
| Analizada | Alta (7.8) | 55% | ⚠ Explotación activa💥 Exploit | Sudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+4 | 30/6/2025 | 17/6/2026 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | |
| Aplazada | Alta (7) | 0.47% | 💥 PoC | LibblockdevAIFreedesktop UdisksAI | 19/6/2025 | 30/6/2026 | A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able… | |
| Analizada | Media (6.5) | 1.4% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 10/6/2025 | 17/6/2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.8) | 1.2% | — | Microsoft Power Automate FOR Desktop | 5/6/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.1% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation. | |
| Analizada | Alta (7.8) | 0.32% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken, a root service writes to a file owned by a normal user. By using a hard link, an attacker can write to an arbitrary file, potentially… | |
| Analizada | Alta (7.8) | 0.28% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is deleted, a root service verifies and modifies the ownership of the snapshot files. By using a symlink, an attacker can change the ownership of… | |
| Analizada | Alta (7.8) | 0.32% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual machine is restored, the prl_vmarchiver tool decompresses the file and writes the content back to its original location using root… | |
| Analizada | Alta (7.5) | 0.57% | — | Devolutions Remote Desktop Manager | 29/5/2025 | 17/6/2026 | Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specific circumstances, entries may be unintentionally moved from user vaults to shared… | |
| Aplazada | Alta (7.4) | 0.82% | — | Gnome-remote-desktopAI | 22/5/2025 | 30/6/2026 | A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files… | |
| Aplazada | Baja (3.3) | 0.17% | — | Github DesktopAIGITAI | 21/5/2025 | 17/6/2026 | GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file in a commit of their making in the history view can cause information disclosure by means of Git attempting to access a network share. This affects… | |
| Analizada | Media (6.1) | 0.18% | — | Nextcloud Desktop | 16/5/2025 | 17/6/2026 | Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes… | |
| Aplazada | Baja (3.9) | 0.14% | — | Hitachi Jp1/it Desktop Management 2 - Smart Device ManagerAI | 15/5/2025 | 17/6/2026 | Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06. | |
| Aplazada | Media (5.3) | 0.16% | — | Hitachi Jp1/it Desktop Management 2 - Smart Device ManagerAI | 15/5/2025 | 17/6/2026 | Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06. | |
| Aplazada | Alta (8.7) | 0.38% | — | Hitachi JP1 IT Desktop Management 2 Smart Device ManagerAI | 15/5/2025 | 17/6/2026 | XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06. | |
| Analizada | Media (6.1) | 0.29% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/5/2025 | 17/6/2026 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access. | |
| Analizada | Media (6.5) | 0.58% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 14/5/2025 | 17/6/2026 | Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.55% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/5/2025 | 17/6/2026 | Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.55% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/5/2025 | 17/6/2026 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.55% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 14/5/2025 | 17/6/2026 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.55% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 14/5/2025 | 17/6/2026 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (8.2) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/5/2025 | 17/6/2026 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. |