Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3979 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.51% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access. | |
| Modificada | Media (4.9) | 0.49% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access. | |
| Analizada | Media (6.5) | 0.51% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+1 | 14/8/2024 | 17/6/2026 | Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an information disclosure via network access. | |
| Analizada | Media (6.5) | 0.56% | — | Zoom RoomsZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 14/8/2024 | 17/6/2026 | Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access. | |
| Analizada | Alta (8.8) | 1.3% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+12 | 13/8/2024 | 17/6/2026 | Clipboard Virtual Channel Extension Remote Code Execution Vulnerability | |
| Aplazada | Media (6.3) | 0.78% | — | Xdg-desktop-portal-hyprlandAIHyprlandAI | 27/7/2024 | 17/6/2026 | xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single quotes are not used when sending a list of app IDs and titles via the environment. | |
| Analizada | Alta (7.8) | 0.26% | — | Canonical Ubuntu Desktop Provision | 23/7/2024 | 17/6/2026 | An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege. | |
| Analizada | Alta (7.4) | 0.60% | — | Devolutions Remote Desktop Manager | 16/7/2024 | 17/6/2026 | Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted website. | |
| Analizada | Media (5.5) | 0.20% | — | Zoom Workplace Desktop | 15/7/2024 | 17/6/2026 | Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access. | |
| Modificada | Media (6.8) | 0.44% | — | Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/7/2024 | 17/6/2026 | Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access. | |
| Analizada | Media (4.4) | 0.14% | — | Zoom RoomsZoom Workplace Desktop | 15/7/2024 | 17/6/2026 | Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authenticated user to conduct a denial of service via local access. | |
| Analizada | Media (5) | 0.16% | — | Zoom Workplace Desktop | 15/7/2024 | 17/6/2026 | Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access. | |
| Modificada | Alta (7.3) | 0.10% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop | 15/7/2024 | 17/6/2026 | Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via local access. | |
| Analizada | Alta (7.5) | 0.43% | — | Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+1 | 15/7/2024 | 17/6/2026 | Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.8) | 0.17% | — | Zoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/7/2024 | 17/6/2026 | Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access. | |
| Analizada | Media (6.3) | 0.11% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop | 15/7/2024 | 17/6/2026 | Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access. | |
| Analizada | Alta (8.5) | 0.21% | — | Citrix Virtual Apps AND Desktops | 10/7/2024 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS | |
| Modificada | Alta (7.3) | 0.56% | — | Docker Desktop | 9/7/2024 | 17/6/2026 | In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/desktop/release-notes/#4290 fixes the issue on MacOS, Linux… | |
| Modificada | Media (5.5) | 0.37% | — | Docker Desktop | 9/7/2024 | 17/6/2026 | In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers mode. | |
| Modificada | Crítica (9.6) | 0.71% | 💥 PoC | Goanother Another Redis Desktop Manager | 5/7/2024 | 17/6/2026 | goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue. | |
| Modificada | Media (6.7) | 0.15% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+384 | 2/7/2024 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges | |
| Analizada | Alta (7.8) | 0.12% | — | HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+349 | 28/6/2024 | 17/6/2026 | A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Aplazada | Media (6.8) | 0.38% | — | Spotfire Enterprise Runtime FOR R - Server EditionAISpotfire Statistics ServicesAISpotfire DesktopAISpotfireAI+1 | 27/6/2024 | 17/6/2026 | Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue… | |
| Analizada | Media (5.5) | 0.15% | — | Canonical Ubuntu Advantage Desktop Daemon | 27/6/2024 | 17/6/2026 | Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext. | |
| Analizada | Alta (7.2) | 0.79% | — | Devolutions Remote Desktop Manager | 26/6/2024 | 17/6/2026 | Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard. |