Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
3979 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.23% | — | Devolutions Remote Desktop ManagerDevolutions Remote Desktop Manager Powershell | 10/2/2025 | 17/6/2026 | Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and… | |
| Analizada | Crítica (9.8) | 0.74% | — | Gnome-remote-desktopCanonical Ubuntu Linux | 31/1/2025 | 17/6/2026 | Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default. | |
| Analizada | Crítica (9.8) | 0.61% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoom Workplace Desktop | 30/1/2025 | 17/6/2026 | Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access. | |
| Analizada | Media (5) | 0.23% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+1 | 30/1/2025 | 17/6/2026 | Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access. | |
| Analizada | Alta (7.8) | 0.21% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+2 | 30/1/2025 | 17/6/2026 | Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.34% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+3 | 30/1/2025 | 17/6/2026 | Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access. | |
| Analizada | Media (6.5) | 0.47% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoom Workplace Desktop | 30/1/2025 | 17/6/2026 | Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a denial of service via network access. | |
| Analizada | Alta (7.8) | 0.26% | — | Oracle Analytics Desktop | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Analytics Desktop executes to compromise Oracle… | |
| Aplazada | Alta (8.7) | 0.49% | — | Belledonne Communications Linphone-desktopAI | 17/1/2025 | 17/6/2026 | Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remote attacker to create a denial-of-service condition. | |
| Aplazada | Media (6.6) | 0.76% | 💥 PoC | Github DesktopAI | 15/1/2025 | 17/6/2026 | GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL. GitHub Desktop relies on Git to perform… | |
| Analizada | Alta (7.8) | 0.75% | — | Microsoft Power Automate FOR Desktop | 14/1/2025 | 17/6/2026 | Microsoft Power Automate Remote Code Execution Vulnerability | |
| Modificada | Media (4.3) | 0.62% | — | Freedesktop Poppler | 23/12/2024 | 17/6/2026 | libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc. | |
| Aplazada | Crítica (9.3) | 0.57% | — | Wapro ERP DesktopAI | 18/12/2024 | 17/6/2026 | Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations. This issue affects Wapro ERP Desktop versions before 8.90.0. | |
| Aplazada | Crítica (9.1) | 0.92% | — | Wapro ERP DesktopAI | 18/12/2024 | 17/6/2026 | Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions before 9.00.0. | |
| Analizada | Alta (8.4) | 1.5% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 12/12/2024 | 17/6/2026 | Remote Desktop Client Remote Code Execution Vulnerability | |
| Analizada | Alta (7.1) | 0.21% | — | Ivanti Desktop & Server Management | 10/12/2024 | 17/6/2026 | Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files. | |
| Analizada | Alta (8.1) | 0.60% | — | Devolutions Remote Desktop Manager | 4/12/2024 | 17/6/2026 | Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested. | |
| Analizada | Media (4.3) | 0.55% | — | Devolutions Remote Desktop Manager | 25/11/2024 | 17/6/2026 | Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature. | |
| Analizada | Media (5.4) | 0.53% | — | Devolutions Remote Desktop Manager | 25/11/2024 | 17/6/2026 | Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching. | |
| Analizada | Media (5.4) | 0.67% | — | Devolutions Remote Desktop Manager | 25/11/2024 | 17/6/2026 | Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions. | |
| Analizada | Alta (7.5) | 0.55% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+2 | 19/11/2024 | 17/6/2026 | Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.47% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+2 | 19/11/2024 | 17/6/2026 | Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.5) | 0.50% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+3 | 19/11/2024 | 17/6/2026 | Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Alta (7.5) | 0.74% | 💥 PoC | Nextcloud Desktop | 15/11/2024 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded… | |
| Aplazada | Media (5) | 0.50% | — | Element WEBAIElement Matrix React SDKAIElement DesktopAI | 12/11/2024 | 17/6/2026 | Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85. |