Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

5106 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.6)0.26%—Desktopalert Pingalert Application Server14/11/202517/6/2026
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.
AnalizadaBaja (3.3)0.09%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive Information because of Incompatible Policies.
AnalizadaMedia (4.1)0.09%—Desktopalert Pingalert Application Server14/11/202517/6/2026
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is a Broken or Risky Cryptographic Algorithm.
AnalizadaCrítica (10)0.31%—Desktopalert Pingalert Application Server14/11/202517/6/2026
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.
AnalizadaAlta (7.8)0.10%—Zoom Workplace Virtual Desktop Infrastructure13/11/202517/6/2026
Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
AnalizadaAlta (7.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+113/11/202517/6/2026
External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaMedia (5.5)0.15%—Zoom Meeting Software Development KITZoom Workplace Desktop13/11/202517/6/2026
External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access.
AnalizadaAlta (7.5)0.27%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+113/11/20257/10/2026
Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaMedia (6.1)0.19%—Zoom Meeting Software Development KITZoom Workplace Desktop13/11/20257/10/2026
Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.
AnalizadaMedia (6.5)0.10%—Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure13/11/20257/10/2026
Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.
AnalizadaMedia (6.5)0.13%—Zoom Workplace Virtual Desktop Infrastructure13/11/20257/10/2026
Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.
AnalizadaAlta (7.8)0.16%—Autodesk 3DS MAX12/11/202517/6/2026
A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
AnalizadaAlta (7.8)0.17%—Autodesk 3DS MAX12/11/202517/6/2026
A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.20%—Autodesk Shared Components7/11/20257/10/2026
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
ModificadaAlta (8.2)0.32%—Anydesk6/11/202517/6/2026
An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this…
ModificadaCrítica (9.8)0.53%—Anydesk6/11/202517/6/2026
An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user…
ModificadaAlta (7.5)0.51%—Anydesk6/11/202517/6/2026
An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL…
ModificadaAlta (7.5)0.32%—Anydesk6/11/202517/6/2026
An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.
AplazadaCrítica (10)0.48%—Villatheme Happy Helpdesk Support Ticket SystemAI6/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code Inclusion.This issue affects HAPPY: from n/a through <= 1.0.7.
AnalizadaAlta (7.8)0.16%—Autodesk Installer6/11/20257/10/2026
A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYSTEM due to an insufficient validation of loaded binaries. An attacker with local and low-privilege access could exploit this to execute code as SYSTEM.
AplazadaAlta (7.8)0.16%💥 PoCTrimble Sketchup DesktopAITrimble Sketchup WebhelperAI31/10/20255/7/2026
DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.
AplazadaAlta (8.8)0.11%—Docker DesktopAI27/10/202517/6/2026
Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desktop: through 4.48.0.
AplazadaMedia (5.8)0.31%—Wpdesk Shopmagic FOR WoocommerceAI22/10/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects ShopMagic: from n/a through <= 4.5.6.
AnalizadaMedia (6.1)0.32%—Mattermost Desktop16/10/202517/6/2026
Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the…
AplazadaMedia (5.3)0.29%—Desknets NEOAI16/10/202517/6/2026
Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications.