Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3979 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.36% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to… | |
| Analizada | Alta (7.8) | 0.37% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to… | |
| Analizada | Alta (7.8) | 0.20% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to… | |
| Analizada | Alta (7.8) | 0.37% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Service Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to… | |
| Analizada | Media (4.3) | 0.42% | — | Oracle WEB Applications Desktop Integrator | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: XML input). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop… | |
| Aplazada | Media (6.3) | 0.47% | — | Vesystem Cloud DesktopAI | 15/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue affects some unknown processing of the file /Public/webuploader/0.1.5/server/fileupload2.php. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely.… | |
| Aplazada | Media (6.3) | 0.47% | — | Vesystem Cloud DesktopAI | 15/4/2024 | 17/6/2026 | A vulnerability classified as critical was found in Vesystem Cloud Desktop up to 20240408. This vulnerability affects unknown code of the file /Public/webuploader/0.1.5/server/fileupload.php. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.8) | 0.19% | — | Weave Desktop | 12/4/2024 | 17/6/2026 | An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework component. | |
| Analizada | Media (4.4) | 0.18% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+264 | 10/4/2024 | 17/6/2026 | Dell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (4.3) | 0.28% | — | Devolutions ServerDevolutions Remote Desktop Manager | 9/4/2024 | 17/6/2026 | Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software… | |
| Analizada | Media (5.9) | 0.42% | — | Devolutions Remote Desktop Manager | 13/3/2024 | 17/6/2026 | Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, under specific circumstances, to access sensitive information via residual files in the temporary directory. | |
| Analizada | Media (6.1) | 0.33% | — | Oracle WEB Applications Desktop Integrator | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications… | |
| Analizada | Media (6.4) | 0.28% | — | HP Elite Mini 600 G9 FirmwareHP Elite Mini 800 G9 FirmwareHP Elite SFF 600 G9 FirmwareHP Elite SFF 800 G9 Firmware+23 | 14/2/2024 | 17/6/2026 | Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities. | |
| Analizada | Media (6.4) | 0.28% | — | HP Elite Mini 600 G9 FirmwareHP Elite Mini 800 G9 FirmwareHP Elite SFF 600 G9 FirmwareHP Elite SFF 800 G9 Firmware+23 | 14/2/2024 | 17/6/2026 | Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities. | |
| Modificada | Media (5.5) | 0.23% | — | Leanote Desktop | 7/2/2024 | 17/6/2026 | Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR. | |
| Modificada | Media (4.4) | 0.16% | — | Dell Optiplex 3000 Micro FirmwareDell Optiplex 3000 Small Form Factor FirmwareDell Optiplex 3000 Tower FirmwareDell Optiplex 5000 Micro Firmware+287 | 6/2/2024 | 17/6/2026 | Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Crítica (9.6) | 1.7% | — | Mate-desktop Engrampa | 5/2/2024 | 17/6/2026 | Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to achieve full Remote Command Execution (RCE) on the target. While handling CPIO archives, the Engrampa Archive manager follows symlink, cpio by default will follow… | |
| Analizada | Alta (7.8) | 28% | ⚠ Explotación activa💥 PoC | Netapp H300s FirmwareNetapp H500s FirmwareNetapp H700s FirmwareNetapp H410s Firmware+14 | 31/1/2024 | 7/8/2026 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when… | |
| Modificada | Media (5.4) | 0.29% | — | Devolutions Remote Desktop Manager | 31/1/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry. | |
| Modificada | Alta (7.8) | 1.1% | 💥 PoC | Mate-desktop Atril | 25/1/2024 | 17/6/2026 | Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted… | |
| Modificada | Alta (7.8) | 0.36% | — | TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+8 | 18/1/2024 | 17/6/2026 | A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context. | |
| Modificada | Media (5.5) | 0.32% | — | TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+8 | 18/1/2024 | 17/6/2026 | A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX… | |
| Modificada | Crítica (9.8) | 2.1% | — | X.org X ServerX.org XwaylandFedoraproject FedoraRedhat Enterprise Linux Desktop+3 | 18/1/2024 | 17/6/2026 | A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow… | |
| Modificada | Alta (7.2) | 47% | — | Citrix Virtual Apps AND Desktops | 18/1/2024 | 17/6/2026 | Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting | |
| Modificada | Alta (7.8) | 0.25% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoomZoom Virtual Desktop Infrastructure | 12/1/2024 | 17/6/2026 | Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access. |