Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3979 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.40%—Devolutions Remote Desktop Manager26/3/202517/6/2026
Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to bypass certain permission restrictions—specifically View Password, Edit Asset, and Edit Permissions by performing specific actions. This issue affects Remote…
AnalizadaCrítica (9.8)0.83%—Mintplexlabs Anythingllm Desktop20/3/202517/6/2026
In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data from the workspace.
AnalizadaBaja (3.3)0.17%—Mattermost Desktop17/3/202517/6/2026
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
AplazadaAlta (7.8)0.12%—Parallels DesktopAI16/3/202517/6/2026
Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM creation routine.
AnalizadaMedia (6.5)1.8%—Devolutions Remote Desktop Manager13/3/202517/6/2026
Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personal Credentials in a shared vault via the clear history feature due to faulty business logic.
AnalizadaMedia (6.5)1.8%—Devolutions Remote Desktop Manager13/3/202517/6/2026
Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows a user exporting a hub data source to include his authenticated session in the export due to faulty business logic.
AplazadaMedia (5.2)0.14%—Xerox Desktop Print ExperienceAI12/3/202517/6/2026
Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low-privileged user to gain SYSTEM-level access.
AnalizadaAlta (8.8)0.45%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (8.8)0.44%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (8.8)0.44%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (8.8)3.2%—Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1211/3/202517/6/2026
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.5)0.25%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.
AplazadaMedia (5.2)0.17%—Docker DesktopAI6/3/202517/6/2026
A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information via application logs. In affected versions, proxy configuration data—potentially including sensitive details—was written to log files in clear text whenever an HTTP GET request was…
AplazadaCrítica (9.9)0.81%—TodesktopAIAnysphere CursorAI1/3/202517/6/2026
ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a postinstall script in package.json. No…
AnalizadaMedia (6.5)0.64%—Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+125/2/202517/6/2026
Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.64%—Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+125/2/202517/6/2026
Buffer overflow in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.
ModificadaMedia (6.5)0.64%—Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+125/2/202517/6/2026
Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+225/2/202517/6/2026
Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
AnalizadaMedia (6.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+225/2/202517/6/2026
Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
AnalizadaAlta (7.5)0.37%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+225/2/202517/6/2026
Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaAlta (8.8)0.61%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+325/2/202517/6/2026
Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (8.8)0.48%—Zoom Meeting Software Development KITZoom RoomsZoom Video Software Development KITZoom Workplace Desktop25/2/202517/6/2026
Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaMedia (5.5)0.19%—Zoom Meeting Software Development KITZoom RoomsZoom Video Software Development KITZoom Workplace Desktop25/2/202517/6/2026
Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of information via local access.
AnalizadaAlta (8.2)0.17%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+38819/2/202517/6/2026
Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AnalizadaAlta (8.1)0.39%—Devolutions Remote Desktop Manager10/2/202517/6/2026
Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack by presenting a certificate for a different host.