Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

3979 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.5)0.34%—Element WEBAIElement Matrix React SDKAIElement DesktopAI12/11/202417/6/2026
Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked. Fixed in element-web 1.11.85.
AplazadaMedia (5.5)0.28%—Chatwork Desktop ApplicationAI28/10/202417/6/2026
Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in the application, an arbitrary file may be downloaded from an external website and executed. As a result, arbitrary code may be executed on the device that…
AnalizadaAlta (7.8)0.22%—Ivanti Desktop & Server Management18/10/202417/6/2026
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
AnalizadaAlta (7.8)0.22%—Ivanti Desktop & Server Management18/10/202417/6/2026
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
AplazadaAlta (8.9)0.47%—Docker DesktopAI16/10/202417/6/2026
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
AplazadaAlta (7)0.59%—Element DesktopAI15/10/202417/6/2026
Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets,…
ModificadaMedia (5.5)0.15%—Devolutions Remote Desktop Manager25/9/202417/6/2026
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
AplazadaCrítica (9.8)1.00%—Parallels DesktopAI23/9/202417/6/2026
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.
AnalizadaMedia (6.5)0.21%—Mattermost Desktop16/9/202417/6/2026
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
AnalizadaMedia (5.3)0.31%—Mattermost Desktop16/9/202417/6/2026
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
AnalizadaAlta (7.8)0.30%—Mattermost Desktop16/9/202417/6/2026
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.
ModificadaCrítica (9.1)0.56%—Nextcloud Desktop16/9/202417/6/2026
In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.
AnalizadaAlta (8.9)1.2%—Docker Desktop12/9/202417/6/2026
A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.
AnalizadaCrítica (9)1.3%—Docker Desktop12/9/202417/6/2026
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.
AplazadaAlta (7.5)0.57%—Gnome Remote DesktopAI2/9/202417/6/2026
A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to…
AnalizadaAlta (7.3)0.17%—Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+34228/8/202417/6/2026
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
ModificadaMedia (6.7)0.24%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop14/8/202417/6/2026
Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.7)0.21%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop14/8/202417/6/2026
Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.5)0.18%—Zoom Meeting Software Development KITZoom Workplace Desktop14/8/202417/6/2026
Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (4.9)0.51%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
ModificadaMedia (4.9)0.49%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
AnalizadaAlta (8.5)0.63%—Zoom RoomsZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure14/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.