Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
538 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the prl_hypervisor kext. The… | |
| Modificada | Alta (8.2) | 0.46% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the handling of network… | |
| Modificada | Alta (8.8) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the prl_hypervisor module. The… | |
| Modificada | Alta (8.2) | 0.48% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the prl_naptd process. The… | |
| Modificada | Media (6) | 0.55% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the OEMNet… | |
| Modificada | Media (6.5) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the prl_hypervisor kext.… | |
| Modificada | Alta (8.8) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handler for… | |
| Modificada | Media (6.5) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handler for… | |
| Modificada | Alta (8.8) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the hypervisor kernel… | |
| Modificada | Crítica (9.9) | 4.0% | — | Parallels Remote Application Server | 24/7/2020 | 17/6/2026 | Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it… | |
| Modificada | Media (6.1) | 1.6% | — | Parall Jspdf | 6/7/2020 | 17/6/2026 | In all versions of the package jspdf, it is possible to use <<script>script> in order to go over the filtering regex. | |
| Modificada | Media (6.1) | 0.97% | — | Parall Jspdf | 6/7/2020 | 17/6/2026 | All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method. | |
| Modificada | Media (4.3) | 0.66% | — | Jenkins Stash Branch Parameter | 2/7/2020 | 17/6/2026 | Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Alta (7.1) | 0.88% | — | Jenkins Parasoft Findings | 16/4/2020 | 17/6/2026 | Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (5.5) | 0.51% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the IOCTL handler. The… | |
| Modificada | Alta (8.8) | 0.55% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the IOCTL handler. The… | |
| Modificada | Media (6.7) | 0.42% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component.… | |
| Modificada | Media (6.7) | 0.37% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component.… | |
| Modificada | Media (4.4) | 0.53% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.1-47117. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI… | |
| Modificada | Media (6.7) | 0.61% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.0-47107 . An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the VGA virtual… | |
| Modificada | Media (6.5) | 0.85% | — | Jenkins Parasoft Environment Manager | 12/2/2020 | 17/6/2026 | Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Dynamic Extended Choice Parameter | 12/2/2020 | 17/6/2026 | Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins GIT Parameter | 12/2/2020 | 17/6/2026 | Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins GIT Parameter | 12/2/2020 | 17/6/2026 | Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission. | |
| Modificada | Alta (7.5) | 1.7% | — | Cpan Parallel\ | 31/1/2020 | 16/6/2026 | Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files. |