Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 0.26% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges. | |
| Analizada | Baja (3.3) | 0.09% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive Information because of Incompatible Policies. | |
| Analizada | Media (4.1) | 0.09% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is a Broken or Risky Cryptographic Algorithm. | |
| Analizada | Crítica (10) | 0.31% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges. | |
| Analizada | Alta (7.8) | 0.10% | — | Zoom Workplace Virtual Desktop Infrastructure | 13/11/2025 | 17/6/2026 | Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Alta (7.5) | 0.32% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 13/11/2025 | 17/6/2026 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (5.5) | 0.15% | — | Zoom Meeting Software Development KITZoom Workplace Desktop | 13/11/2025 | 17/6/2026 | External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access. | |
| Analizada | Alta (7.5) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 13/11/2025 | 7/10/2026 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (6.1) | 0.19% | — | Zoom Meeting Software Development KITZoom Workplace Desktop | 13/11/2025 | 7/10/2026 | Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access. | |
| Analizada | Media (6.5) | 0.10% | — | Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 13/11/2025 | 7/10/2026 | Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access. | |
| Analizada | Media (6.5) | 0.13% | — | Zoom Workplace Virtual Desktop Infrastructure | 13/11/2025 | 7/10/2026 | Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access. | |
| Analizada | Alta (7.8) | 0.16% | — | Autodesk 3DS MAX | 12/11/2025 | 17/6/2026 | A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.17% | — | Autodesk 3DS MAX | 12/11/2025 | 17/6/2026 | A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.20% | — | Autodesk Shared Components | 7/11/2025 | 7/10/2026 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (8.2) | 0.32% | — | Anydesk | 6/11/2025 | 17/6/2026 | An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this… | |
| Modificada | Crítica (9.8) | 0.53% | — | Anydesk | 6/11/2025 | 17/6/2026 | An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user… | |
| Modificada | Alta (7.5) | 0.51% | — | Anydesk | 6/11/2025 | 17/6/2026 | An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL… | |
| Modificada | Alta (7.5) | 0.32% | — | Anydesk | 6/11/2025 | 17/6/2026 | An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID. | |
| Aplazada | Crítica (10) | 0.48% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 6/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code Inclusion.This issue affects HAPPY: from n/a through <= 1.0.7. | |
| Analizada | Alta (7.8) | 0.16% | — | Autodesk Installer | 6/11/2025 | 7/10/2026 | A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYSTEM due to an insufficient validation of loaded binaries. An attacker with local and low-privilege access could exploit this to execute code as SYSTEM. | |
| Aplazada | Alta (7.8) | 0.16% | 💥 PoC | Trimble Sketchup DesktopAITrimble Sketchup WebhelperAI | 31/10/2025 | 5/7/2026 | DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe. | |
| Aplazada | Alta (8.8) | 0.11% | — | Docker DesktopAI | 27/10/2025 | 17/6/2026 | Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desktop: through 4.48.0. | |
| Aplazada | Media (5.8) | 0.31% | — | Wpdesk Shopmagic FOR WoocommerceAI | 22/10/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects ShopMagic: from n/a through <= 4.5.6. | |
| Analizada | Media (6.1) | 0.32% | — | Mattermost Desktop | 16/10/2025 | 17/6/2026 | Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the… | |
| Aplazada | Media (5.3) | 0.29% | — | Desknets NEOAI | 16/10/2025 | 17/6/2026 | Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications. |