Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
5106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.25% | — | Todesktop Builder | 23/1/2026 | 17/6/2026 | Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with renderer-context access to invoke external protocol handlers without sufficient validation. | |
| Analizada | Crítica (9.8) | 0.27% | — | Todesktop Builder | 23/1/2026 | 17/6/2026 | An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to spoof backend responses by exploiting insufficient certificate validation. | |
| Aplazada | Alta (8.8) | 1.3% | — | MCP Manager FOR Claude DesktopAI | 23/1/2026 | 17/6/2026 | MCP Manager for Claude Desktop execute-command Command Injection Sandbox Escape Vulnerability. This vulnerability allows remote attackers to bypass the sandbox on affected installations of MCP Manager for Claude Desktop. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Media (6) | 0.22% | — | Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+52 | 22/1/2026 | 6/10/2026 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline… | |
| Modificada | Alta (8.1) | 0.67% | — | Autodesk Fusion | 22/1/2026 | 17/6/2026 | A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the… | |
| Modificada | Alta (8.1) | 0.55% | — | Autodesk Fusion | 22/1/2026 | 17/6/2026 | A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current… | |
| Modificada | Alta (8.1) | 0.69% | — | Autodesk Fusion | 22/1/2026 | 17/6/2026 | A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute… | |
| Analizada | Media (4.6) | 0.51% | — | Telegram Desktop | 16/1/2026 | 17/6/2026 | Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized message payload. Attackers can generate a 9 million byte buffer and paste it into the messaging interface to trigger an application crash. | |
| Analizada | Media (5.3) | 0.22% | — | Quest Kace Desktop Authority | 12/1/2026 | 17/6/2026 | Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication | |
| Analizada | Baja (3.3) | 0.20% | — | Devolutions Remote Desktop Manager | 8/1/2026 | 17/6/2026 | Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0 on Windows allows an external observer to view a password on screen via a defective masking feature, for example during physical observation or screen sharing. | |
| Modificada | Media (5.4) | 0.23% | — | Edubusinesssolutions Print Shop PRO Webdesk | 8/1/2026 | 17/6/2026 | Cross-Site Scripting (XSS) is present on the ctl00_Content01_fieldValue parameters on the /psp/appNet/TemplateOrder/TemplatePreview.aspx endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). User-supplied input is stored and later rendered in HTML pages without proper output… | |
| Modificada | Media (6.1) | 0.26% | — | Edubusinesssolutions Print Shop PRO Webdesk | 8/1/2026 | 17/6/2026 | Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.76). Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to… | |
| Modificada | Crítica (9.8) | 0.55% | — | Edubusinesssolutions Print Shop PRO Webdesk | 8/1/2026 | 17/6/2026 | SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). Unsanitized user input is incorporated directly into SQL queries without proper parameterization or escaping. This… | |
| Modificada | Media (6.8) | 0.18% | — | Edubusinesssolutions Print Shop PRO Webdesk | 8/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.76). The application does not implement proper CSRF tokens or other other protective measures, allowing a remote attacker to trick authenticated users into unknowingly executing… | |
| Modificada | Crítica (9.1) | 0.54% | — | Edubusinesssolutions Print Shop PRO Webdesk | 8/1/2026 | 17/6/2026 | There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69) that enables remote attacker to create financial discrepancies by purchasing items with a negative quantity. This vulnerability is possible due to reliance on… | |
| Aplazada | Media (4.3) | 0.16% | — | Helpdesk Contact FormAI | 7/1/2026 | 17/6/2026 | The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation on the handle_query_args() function. This makes it possible for unauthenticated attackers to update the plugin's license ID and… | |
| Analizada | Alta (7.5) | 0.41% | 💥 PoC | Inmusicbrands Engine DJ Desktop | 30/12/2025 | 17/6/2026 | inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths. | |
| Aplazada | Media (5.3) | 0.22% | — | Wpdesk Shopmagic FOR WoocommerceAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShopMagic: from n/a through <= 4.7.2. | |
| Analizada | Alta (7.3) | 0.23% | — | Libredesk | 27/12/2025 | 7/10/2026 | Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding notes via POST /api/v1/contacts/{id}/notes, the backend automatically wraps user input in <p> tags. However, by intercepting the request and removing… | |
| Aplazada | Alta (7.8) | 0.16% | — | Tradingview DesktopAIElectronAI | 23/12/2025 | 17/6/2026 | TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Alta (7.8) | 0.21% | — | Sodapdf Soda PDF Desktop | 23/12/2025 | 17/6/2026 | Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.45% | — | Sodapdf Soda PDF Desktop | 23/12/2025 | 17/6/2026 | Soda PDF Desktop CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Aplazada | Media (5.3) | 0.22% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 23/12/2025 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.9. | |
| Aplazada | Alta (7.2) | 0.23% | — | Elex Wordpress Helpdesk Customer Ticketing SystemAI | 21/12/2025 | 28/9/2026 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (5.3) | 0.21% | — | Wbiz DeskAI | 18/12/2025 | 17/6/2026 | WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.php. Attackers can inject crafted SQL statements using UNION-based techniques to extract sensitive database information by sending malformed requests to the ticket… |