Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
5106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.22% | — | Autodesk Shared Components | 18/2/2026 | 17/6/2026 | A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Aplazada | Alta (7.2) | 0.63% | — | Wpdesk Product Addons FOR WoocommerceAI | 18/2/2026 | 17/6/2026 | The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 3.1.0. This is due to insufficient input validation of the 'operator' field in conditional logic rules within the evalConditions() function, which passes… | |
| Analizada | Media (6.5) | 0.25% | — | Mattermost Desktop | 16/2/2026 | 17/6/2026 | Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577 | |
| Aplazada | Alta (8.4) | 0.62% | — | Free Desktop ClockAI | 5/2/2026 | 17/6/2026 | Free Desktop Clock 3.0 contains a stack overflow vulnerability in the Time Zones display name input that allows attackers to overwrite Structured Exception Handler (SEH) registers. Attackers can exploit the vulnerability by crafting a malicious Unicode input that triggers an access violation and potentially execute… | |
| Aplazada | Media (5.3) | 0.30% | — | Elex Wordpress Helpdesk Customer Ticketing SystemAI | 5/2/2026 | 17/6/2026 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.5. This is due to missing capability checks on the eh_crm_ticket_general function combined with a shared nonce that is exposed to low-privileged users. This… | |
| Analizada | Alta (7.8) | 0.21% | — | Autodesk 3DS MAX | 4/2/2026 | 17/6/2026 | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.21% | — | Autodesk 3DS MAX | 4/2/2026 | 17/6/2026 | A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized. | |
| Modificada | Alta (8.4) | 0.19% | — | Autodesk 3DS MAX | 4/2/2026 | 17/6/2026 | A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (8.4) | 0.22% | — | Autodesk 3DS MAX | 4/2/2026 | 17/6/2026 | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Aplazada | Alta (7.8) | 0.24% | — | Autodesk ArnoldAIAutodesk 3DS MAXAI | 4/2/2026 | 17/6/2026 | A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (8.4) | 0.19% | — | Autodesk 3DS MAX | 4/2/2026 | 17/6/2026 | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (8.4) | 0.19% | — | Autodesk 3DS MAX | 4/2/2026 | 17/6/2026 | A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Aplazada | Media (6.7) | 0.23% | — | Docker DesktopAI | 4/2/2026 | 17/6/2026 | Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling of the C:\ProgramData\DockerDesktop directory. The installer creates this directory without proper ownership verification, creating two exploitation scenarios: Scenario 1 (Persistent Attack): If a… | |
| Aplazada | Media (5.1) | 0.17% | — | Maian Support HelpdeskAI | 3/2/2026 | 17/6/2026 | Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system. | |
| Aplazada | Alta (8.4) | 0.39% | — | Remote Desktop AuditAI | 3/2/2026 | 17/6/2026 | Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wizard file import process. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) bypass and execute shellcode when importing computer… | |
| Aplazada | Media (5.1) | 0.28% | — | Zendesk Sweethawk SurveyAI | 3/2/2026 | 17/6/2026 | Zendesk SweetHawk Survey 1.6 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through support ticket submissions. Attackers can insert XSS payloads like script tags into ticket text that automatically execute when survey pages are loaded by other users. | |
| Analizada | Alta (8.5) | 0.19% | — | Anydesk | 3/2/2026 | 7/10/2026 | AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path to place malicious files in service executable locations, potentially gaining elevated system… | |
| Analizada | Alta (8.8) | 0.31% | — | Linuxfoundation Podman Desktop | 28/1/2026 | 17/6/2026 | Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnerability in Podman Desktop prior to version 1.25.1 allows any extension to completely circumvent permission checks and gain unauthorized access to all authentication sessions. The `isAccessAllowed()`… | |
| Analizada | Crítica (9.8) | 61% | 💥 Exploit | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk. | |
| Modificada | Crítica (9.8) | 68% | — | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. | |
| Modificada | Crítica (9.8) | 52% | 💥 Exploit | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication. | |
| Analizada | Crítica (9.8) | 84% | ⚠ Explotación activa💥 Exploit | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. | |
| Analizada | Alta (7.5) | 0.59% | — | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions. | |
| Analizada | Crítica (9.8) | 74% | ⚠ Explotación activa💥 Exploit | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality. | |
| Analizada | Media (5.9) | 0.30% | — | Todesktop Builder | 23/1/2026 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload. |