Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

3979 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)0.51%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
ModificadaMedia (4.9)0.49%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
AnalizadaMedia (6.5)0.51%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+114/8/202417/6/2026
Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an information disclosure via network access.
AnalizadaMedia (6.5)0.56%—Zoom RoomsZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure14/8/202417/6/2026
Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.
AnalizadaAlta (8.8)1.3%—Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+1213/8/202417/6/2026
Clipboard Virtual Channel Extension Remote Code Execution Vulnerability
AplazadaMedia (6.3)0.78%—Xdg-desktop-portal-hyprlandAIHyprlandAI27/7/202417/6/2026
xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single quotes are not used when sending a list of app IDs and titles via the environment.
AnalizadaAlta (7.8)0.26%—Canonical Ubuntu Desktop Provision23/7/202417/6/2026
An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.
AnalizadaAlta (7.4)0.60%—Devolutions Remote Desktop Manager16/7/202417/6/2026
Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted website.
AnalizadaMedia (5.5)0.20%—Zoom Workplace Desktop15/7/202417/6/2026
Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.
ModificadaMedia (6.8)0.44%—Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure15/7/202417/6/2026
Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access.
AnalizadaMedia (4.4)0.14%—Zoom RoomsZoom Workplace Desktop15/7/202417/6/2026
Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authenticated user to conduct a denial of service via local access.
AnalizadaMedia (5)0.16%—Zoom Workplace Desktop15/7/202417/6/2026
Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.
ModificadaAlta (7.3)0.10%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop15/7/202417/6/2026
Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via local access.
AnalizadaAlta (7.5)0.43%—Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+115/7/202417/6/2026
Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.
AnalizadaAlta (7.8)0.17%—Zoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure15/7/202417/6/2026
Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.
AnalizadaMedia (6.3)0.11%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop15/7/202417/6/2026
Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access.
AnalizadaAlta (8.5)0.21%—Citrix Virtual Apps AND Desktops10/7/202417/6/2026
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS
ModificadaAlta (7.3)0.56%—Docker Desktop9/7/202417/6/2026
In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/desktop/release-notes/#4290 fixes the issue on MacOS, Linux…
ModificadaMedia (5.5)0.37%—Docker Desktop9/7/202417/6/2026
In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers mode.
ModificadaCrítica (9.6)0.71%💥 PoCGoanother Another Redis Desktop Manager5/7/202417/6/2026
goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.
ModificadaMedia (6.7)0.15%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+3842/7/202417/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
AnalizadaAlta (7.8)0.12%—HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+34928/6/202417/6/2026
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
AplazadaMedia (6.8)0.38%—Spotfire Enterprise Runtime FOR R - Server EditionAISpotfire Statistics ServicesAISpotfire DesktopAISpotfireAI+127/6/202417/6/2026
Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue…
AnalizadaMedia (5.5)0.15%—Canonical Ubuntu Advantage Desktop Daemon27/6/202417/6/2026
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
AnalizadaAlta (7.2)0.79%—Devolutions Remote Desktop Manager26/6/202417/6/2026
Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.