Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3979 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (10) | 0.32% | — | Parallels Desktop | 21/6/2024 | 17/6/2026 | Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 0.78% | — | Freedesktop PopplerRedhat Enterprise Linux | 21/6/2024 | 17/6/2026 | A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service. | |
| Modificada | Media (6.7) | 0.25% | — | Parallels Desktop | 20/6/2024 | 17/6/2026 | Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order… | |
| Modificada | Alta (7.8) | 0.29% | — | Parallels Desktop | 20/6/2024 | 17/6/2026 | Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local attackers to downgrade Parallels software on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order… | |
| Analizada | Crítica (9.8) | 0.92% | — | Devolutions Remote Desktop Manager | 17/6/2024 | 17/6/2026 | Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an RDM instance to bypass the vault master password via the offline mode feature. | |
| Analizada | Media (4.7) | 0.50% | — | Devolutions Remote Desktop Manager | 17/6/2024 | 17/6/2026 | Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials configured on the data source via stealing the configuration file. | |
| Modificada | Alta (7.8) | 0.32% | — | Nextcloud Desktop | 14/6/2024 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the Nextcloud Desktop client is… | |
| Modificada | Media (6.1) | 0.30% | — | Mattermost Desktop | 14/6/2024 | 17/6/2026 | Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes. | |
| Modificada | Baja (3.3) | 0.19% | — | Mattermost Desktop | 14/6/2024 | 17/6/2026 | Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS. | |
| Analizada | Alta (8.8) | 1.2% | — | Dropbox Desktop | 13/6/2024 | 17/6/2026 | Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Modificada | Alta (7.1) | 0.30% | — | Adobe Creative Cloud Desktop Application | 13/6/2024 | 17/6/2026 | Creative Cloud Desktop versions 6.1.0.587 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to load and execute malicious libraries, leading to arbitrary file delete. Exploitation of this issue… | |
| Analizada | Media (6.8) | 0.18% | — | HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+22 | 10/6/2024 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities. | |
| Analizada | Media (6.8) | 0.17% | — | HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+22 | 10/6/2024 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities. | |
| Analizada | Crítica (9.6) | 0.97% | — | Mintplexlabs Anythingllm DesktopMintplexlabs Anythingllm Docker | 6/6/2024 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability arises from the application's feature to fetch and embed content from websites into workspaces, which can be exploited… | |
| Analizada | Alta (7.8) | 0.10% | — | Zoom Workplace Virtual Desktop Infrastructure | 15/5/2024 | 17/6/2026 | Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.41% | — | Zoom Meeting Software Development KITZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/5/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access. | |
| Aplazada | Alta (7.7) | 0.28% | — | Gehealthcare Common Service DesktopAI | 14/5/2024 | 17/6/2026 | Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component | |
| Aplazada | Media (6.2) | 0.28% | — | Gehealthcare Common Service DesktopAI | 14/5/2024 | 17/6/2026 | Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component | |
| Analizada | Alta (7.8) | 0.21% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (8.3) | 0.76% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop virtio-gpu Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Parallels Desktop. User interaction is required to exploit this vulnerability in that the target in a guest system must visit a… | |
| Analizada | Alta (7.8) | 0.69% | 💥 PoC | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.97% | — | Ivanti Pulse Secure Desktop ClientIvanti Pulse Secure Installer ServiceIvanti Secure Access Client | 3/5/2024 | 17/6/2026 | Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pulse Secure Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Alta (7.8) | 0.32% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit… | |
| Analizada | Alta (7.5) | 0.40% | 💥 PoC | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Toolgate Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order… | |
| Analizada | Alta (8.2) | 1.3% | 💥 PoC | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Toolgate Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to… |