Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3979 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.15% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/5/2025 | 17/6/2026 | Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Alta (8.8) | 1.4% | — | Microsoft Remote DesktopMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 13/5/2025 | 17/6/2026 | Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Alta (7.8) | 0.22% | — | Solidworks EdrawingsAISolidworks DesktopAI | 2/5/2025 | 17/6/2026 | Use-After-Free vulnerability exists in the SLDPRT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file. | |
| Aplazada | Alta (7.8) | 0.21% | — | 3DS Solidworks EdrawingsAI3DS Solidworks DesktopAI | 2/5/2025 | 17/6/2026 | Out-Of-Bounds Write vulnerability exists in the OBJ file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted OBJÂ file. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Azure Virtual Desktop | 30/4/2025 | 17/6/2026 | Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (4.3) | 0.15% | — | Docker DesktopAI | 29/4/2025 | 17/6/2026 | Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile is used to enforce organization sign-in, the RAM policies are not being applied, which would allow Docker Desktop users to pull down… | |
| Aplazada | Media (5.2) | 0.17% | — | Docker DesktopAI | 29/4/2025 | 17/6/2026 | Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain sensitive credentials information and further use it… | |
| Analizada | Alta (7.3) | 0.25% | — | Docker Desktop | 28/4/2025 | 17/6/2026 | A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During an update, Docker Desktop attempts to delete files and subdirectories under the path C:\ProgramData\Docker\config with high privileges.… | |
| Analizada | Baja (3.3) | 0.11% | — | Freedesktop Poppler | 18/4/2025 | 17/6/2026 | NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries. | |
| Aplazada | Crítica (9.3) | 0.27% | — | Work Desktop FOR MACAI | 17/4/2025 | 17/6/2026 | Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions 10.8.1.46 and earlier allows attackers to execute arbitrary commands via unauthorized access to the Agent service. This has been remediated in Work Desktop for Mac version 10.8.2.33. | |
| Analizada | Media (5.7) | 0.90% | — | Microsoft Power Automate FOR Desktop | 15/4/2025 | 17/6/2026 | Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. | |
| Aplazada | Crítica (9) | 0.92% | — | Jupyter Remote Desktop ProxyAITigervncAI | 15/4/2025 | 17/6/2026 | Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the… | |
| Modificada | Crítica (9.4) | 0.67% | — | Tibco Spotfire Enterprise Runtime FOR RTibco Spotfire Statistics ServicesTibco Spotfire AnalystTibco Spotfire Deployment KIT+2 | 9/4/2025 | 17/6/2026 | Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution | |
| Analizada | Media (6.7) | 0.17% | — | Dell Latitude 3140 2in1 FirmwareDell Latitude 3320 FirmwareDell Latitude 3330 FirmwareDell Latitude 3340 Firmware+257 | 9/4/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. | |
| Analizada | Alta (8) | 1.5% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 8/4/2025 | 17/6/2026 | Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 0.40% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 8/4/2025 | 17/6/2026 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.42% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 8/4/2025 | 17/6/2026 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (5.5) | 0.16% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop | 8/4/2025 | 17/6/2026 | Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access. | |
| Modificada | Media (5.2) | 0.24% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 8/4/2025 | 17/6/2026 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. | |
| Modificada | Media (5.2) | 0.26% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 8/4/2025 | 17/6/2026 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. | |
| Modificada | Alta (7.1) | 0.25% | — | Freedesktop Poppler | 5/4/2025 | 17/6/2026 | Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check. | |
| Modificada | Media (5.5) | 0.27% | — | Freedesktop Poppler | 5/4/2025 | 17/6/2026 | A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN. | |
| Modificada | Media (6.8) | 0.41% | — | Devolutions Remote Desktop Manager | 26/3/2025 | 17/6/2026 | Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy". This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25,… | |
| Analizada | Media (5.4) | 0.42% | — | Devolutions Remote Desktop Manager | 26/3/2025 | 17/6/2026 | Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event, via the use of the autotyping functionality. This issue affects Remote Desktop Manager versions from 2025.1.24 through… | |
| Analizada | Baja (3.6) | 0.17% | — | Devolutions Remote Desktop Manager | 26/3/2025 | 17/6/2026 | Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration different from the one mandated by the system administrators. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions… |