Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

5106 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.29%—Desknet NEOAI16/10/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.
AplazadaMedia (4.6)0.30%—Desknet NEOAI16/10/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.
AplazadaMedia (4.8)0.29%—Desknet NEOAI16/10/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.
AplazadaMedia (5.1)0.32%—Desknet WEB ServerAI16/10/202517/6/2026
Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a user’s web browser.
AplazadaMedia (4.8)0.29%—Desknets NEOAI16/10/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0–V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.
AplazadaMedia (5.3)0.27%—Desknet NEOAI16/10/202530/9/2026
desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious AppSuite applications.
AnalizadaMedia (6.5)1.8%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure15/10/202517/6/2026
Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
AnalizadaMedia (6.1)0.29%—Cisco Desk Phone 9871 FirmwareCisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 Firmware+1315/10/202517/6/2026
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web UI. This vulnerability exists because the web UI of an affected…
AnalizadaAlta (7.5)0.48%—Cisco Desk Phone 9871 FirmwareCisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 Firmware+1315/10/202517/6/2026
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to a buffer overflow when an affected…
AnalizadaAlta (8.8)0.60%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+1414/10/202517/6/2026
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.5)0.30%—Mattermost Desktop13/10/202517/6/2026
Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.
AnalizadaBaja (2.1)4.3%—Wonderwhy-er Desktopcommandermcp8/10/202517/6/2026
A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
AnalizadaBaja (2.1)3.5%—Wonderwhy-er Desktopcommandermcp8/10/202517/6/2026
A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component Absolute Path Handler. Such manipulation leads to os command injection. The attack may be performed from remote. The exploit has…
AnalizadaBaja (1.1)0.25%—Wonderwhy-er Desktopcommandermcp8/10/202517/6/2026
A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of the file src/tools/filesystem.ts. The manipulation leads to symlink following. The attack can only be performed from a local environment. The attack's complexity is…
AplazadaAlta (8.7)0.14%—Docker DesktopAI26/9/202517/6/2026
In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-container-isolation/ ) enabled, an administrator can utilize the command restrictions feature…
AplazadaAlta (7.1)0.12%—Flytedesk DigitalAI26/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in flytedesk Flytedesk Digital flytedesk-digital allows Stored XSS.This issue affects Flytedesk Digital: from n/a through <= 20181101.
ModificadaAlta (7.8)0.18%—Autodesk Revit23/9/202517/6/2026
A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
AnalizadaAlta (8.7)0.45%—Autodesk Fusion23/9/202517/6/2026
A maliciously crafted HTML payload, when rendered by the Autodesk Fusion desktop application, can trigger a Stored Cross-site Scripting (XSS) vulnerability. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.
AnalizadaCrítica (9.8)90%⚠ Explotación activa💥 ExploitSolarwinds WEB Help Desk23/9/202517/6/2026
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of…
AnalizadaAlta (7.8)0.18%—Autodesk Shared Components22/9/202517/6/2026
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
AplazadaAlta (7.1)0.15%—Wpdesk Flexible PDF Invoices FOR WoocommerceAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress flexible-invoices allows Cross Site Request Forgery.This issue affects Flexible PDF Invoices for WooCommerce & WordPress: from n/a through <= 6.0.13.
AplazadaMedia (4.3)0.25%—Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI22/9/20251/10/2026
Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.1.
AplazadaAlta (7.8)0.17%—Solidworks EdrawingsAISolidworks DesktopAI17/9/202525/9/2026
An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary code while opening a specially crafted PAR file.
AnalizadaAlta (7.8)0.17%—Autodesk Autocad Plant 3DAutodesk Advance SteelAutodesk Civil 3DAutodesk Autocad LT+716/9/202517/6/2026
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
AnalizadaAlta (7.8)0.17%—Autodesk RevitAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+716/9/202517/6/2026
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.