Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
3979 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.5) | 0.34% | — | Element WEBAIElement Matrix React SDKAIElement DesktopAI | 12/11/2024 | 17/6/2026 | Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked. Fixed in element-web 1.11.85. | |
| Aplazada | Media (5.5) | 0.28% | — | Chatwork Desktop ApplicationAI | 28/10/2024 | 17/6/2026 | Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in the application, an arbitrary file may be downloaded from an external website and executed. As a result, arbitrary code may be executed on the device that… | |
| Analizada | Alta (7.8) | 0.22% | — | Ivanti Desktop & Server Management | 18/10/2024 | 17/6/2026 | Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector. | |
| Analizada | Alta (7.8) | 0.22% | — | Ivanti Desktop & Server Management | 18/10/2024 | 17/6/2026 | Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector. | |
| Aplazada | Alta (8.9) | 0.47% | — | Docker DesktopAI | 16/10/2024 | 17/6/2026 | Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view. | |
| Aplazada | Alta (7) | 0.59% | — | Element DesktopAI | 15/10/2024 | 17/6/2026 | Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets,… | |
| Modificada | Media (5.5) | 0.15% | — | Devolutions Remote Desktop Manager | 25/9/2024 | 17/6/2026 | An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions | |
| Aplazada | Crítica (9.8) | 1.00% | — | Parallels DesktopAI | 23/9/2024 | 17/6/2026 | A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root. | |
| Analizada | Media (6.5) | 0.21% | — | Mattermost Desktop | 16/9/2024 | 17/6/2026 | Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access. | |
| Analizada | Media (5.3) | 0.31% | — | Mattermost Desktop | 16/9/2024 | 17/6/2026 | Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs. | |
| Analizada | Alta (7.8) | 0.30% | — | Mattermost Desktop | 16/9/2024 | 17/6/2026 | Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine. | |
| Modificada | Crítica (9.1) | 0.56% | — | Nextcloud Desktop | 16/9/2024 | 17/6/2026 | In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4. | |
| Analizada | Alta (8.9) | 1.2% | — | Docker Desktop | 12/9/2024 | 17/6/2026 | A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2. | |
| Analizada | Crítica (9) | 1.3% | — | Docker Desktop | 12/9/2024 | 17/6/2026 | A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2. | |
| Aplazada | Alta (7.5) | 0.57% | — | Gnome Remote DesktopAI | 2/9/2024 | 17/6/2026 | A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to… | |
| Analizada | Alta (7.3) | 0.17% | — | Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+342 | 28/8/2024 | 17/6/2026 | Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service. | |
| Modificada | Media (6.7) | 0.24% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop | 14/8/2024 | 17/6/2026 | Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.7) | 0.21% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop | 14/8/2024 | 17/6/2026 | Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.18% | — | Zoom Meeting Software Development KITZoom Workplace Desktop | 14/8/2024 | 17/6/2026 | Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.57% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.57% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.57% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (4.9) | 0.51% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access. | |
| Modificada | Media (4.9) | 0.49% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access. | |
| Analizada | Alta (8.5) | 0.63% | — | Zoom RoomsZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 14/8/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access. |