Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

3979 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.23%—Devolutions Remote Desktop ManagerDevolutions Remote Desktop Manager Powershell10/2/202517/6/2026
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and…
AnalizadaCrítica (9.8)0.74%—Gnome-remote-desktopCanonical Ubuntu Linux31/1/202517/6/2026
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
AnalizadaCrítica (9.8)0.61%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Workplace Desktop30/1/202517/6/2026
Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access.
AnalizadaMedia (5)0.23%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+130/1/202517/6/2026
Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access.
AnalizadaAlta (7.8)0.21%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+230/1/202517/6/2026
Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.5)0.34%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+330/1/202517/6/2026
Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access.
AnalizadaMedia (6.5)0.47%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Workplace Desktop30/1/202517/6/2026
Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a denial of service via network access.
AnalizadaAlta (7.8)0.26%—Oracle Analytics Desktop21/1/202517/6/2026
Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Analytics Desktop executes to compromise Oracle…
AplazadaAlta (8.7)0.49%—Belledonne Communications Linphone-desktopAI17/1/202517/6/2026
Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remote attacker to create a denial-of-service condition.
AplazadaMedia (6.6)0.76%💥 PoCGithub DesktopAI15/1/202517/6/2026
GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL. GitHub Desktop relies on Git to perform…
AnalizadaAlta (7.8)0.75%—Microsoft Power Automate FOR Desktop14/1/202517/6/2026
Microsoft Power Automate Remote Code Execution Vulnerability
ModificadaMedia (4.3)0.62%—Freedesktop Poppler23/12/202417/6/2026
libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.
AplazadaCrítica (9.3)0.57%—Wapro ERP DesktopAI18/12/202417/6/2026
Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations. This issue affects Wapro ERP Desktop versions before 8.90.0.
AplazadaCrítica (9.1)0.92%—Wapro ERP DesktopAI18/12/202417/6/2026
Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions before 9.00.0.
AnalizadaAlta (8.4)1.5%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+1312/12/202417/6/2026
Remote Desktop Client Remote Code Execution Vulnerability
AnalizadaAlta (7.1)0.21%—Ivanti Desktop & Server Management10/12/202417/6/2026
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.
AnalizadaAlta (8.1)0.60%—Devolutions Remote Desktop Manager4/12/202417/6/2026
Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested.
AnalizadaMedia (4.3)0.55%—Devolutions Remote Desktop Manager25/11/202417/6/2026
Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.
AnalizadaMedia (5.4)0.53%—Devolutions Remote Desktop Manager25/11/202417/6/2026
Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.
AnalizadaMedia (5.4)0.67%—Devolutions Remote Desktop Manager25/11/202417/6/2026
Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.
AnalizadaAlta (7.5)0.55%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+219/11/202417/6/2026
Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.47%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+219/11/202417/6/2026
Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access.
AnalizadaAlta (7.5)0.50%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+319/11/202417/6/2026
Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaAlta (7.5)0.74%💥 PoCNextcloud Desktop15/11/202417/6/2026
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded…
AplazadaMedia (5)0.50%—Element WEBAIElement Matrix React SDKAIElement DesktopAI12/11/202417/6/2026
Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.