Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

538 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.53%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the prl_hypervisor kext. The…
ModificadaAlta (8.2)0.46%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the handling of network…
ModificadaAlta (8.8)0.53%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the prl_hypervisor module. The…
ModificadaAlta (8.2)0.48%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the prl_naptd process. The…
ModificadaMedia (6)0.55%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the OEMNet…
ModificadaMedia (6.5)0.53%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the prl_hypervisor kext.…
ModificadaAlta (8.8)0.53%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handler for…
ModificadaMedia (6.5)0.53%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handler for…
ModificadaAlta (8.8)0.53%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the hypervisor kernel…
ModificadaCrítica (9.9)4.0%—Parallels Remote Application Server24/7/202017/6/2026
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it…
ModificadaMedia (6.1)1.6%—Parall Jspdf6/7/202017/6/2026
In all versions of the package jspdf, it is possible to use <<script>script> in order to go over the filtering regex.
ModificadaMedia (6.1)0.97%—Parall Jspdf6/7/202017/6/2026
All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.
ModificadaMedia (4.3)0.66%—Jenkins Stash Branch Parameter2/7/202017/6/2026
Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
ModificadaAlta (7.1)0.88%—Jenkins Parasoft Findings16/4/202017/6/2026
Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (5.5)0.51%—Parallels Desktop23/3/202017/6/2026
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the IOCTL handler. The…
ModificadaAlta (8.8)0.55%—Parallels Desktop23/3/202017/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the IOCTL handler. The…
ModificadaMedia (6.7)0.42%—Parallels Desktop23/3/202017/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component.…
ModificadaMedia (6.7)0.37%—Parallels Desktop23/3/202017/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component.…
ModificadaMedia (4.4)0.53%—Parallels Desktop23/3/202017/6/2026
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.1-47117. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI…
ModificadaMedia (6.7)0.61%—Parallels Desktop23/3/202017/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.0-47107 . An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the VGA virtual…
ModificadaMedia (6.5)0.85%—Jenkins Parasoft Environment Manager12/2/202017/6/2026
Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaMedia (4.3)0.69%—Jenkins Dynamic Extended Choice Parameter12/2/202017/6/2026
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaMedia (5.4)0.73%—Jenkins GIT Parameter12/2/202017/6/2026
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.
ModificadaMedia (5.4)0.73%—Jenkins GIT Parameter12/2/202017/6/2026
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.
ModificadaAlta (7.5)1.7%—Cpan Parallel\31/1/202016/6/2026
Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.