Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3979 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)2.4%—Mate-desktop Atril12/1/202417/6/2026
Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the target system when the target user opens a crafted document or clicks on a crafted link/URL using a maliciously crafted CBT document which is a…
ModificadaMedia (6.5)0.57%—FreeipaFedoraproject FedoraRedhat Codeready Linux BuilderRedhat Enterprise Linux+1710/1/202417/6/2026
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration…
ModificadaMedia (4.4)0.17%—Devolutions Remote Desktop Manager21/12/202317/6/2026
Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature. This affects only SQL data sources.
ModificadaMedia (6.5)0.40%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom13/12/202317/6/2026
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (8.8)0.99%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom13/12/202317/6/2026
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
ModificadaCrítica (9.8)0.73%—Devolutions Remote Desktop Manager12/12/202317/6/2026
Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.
ModificadaAlta (8.8)4.3%—PostgresqlRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUS+1710/12/202317/6/2026
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data.…
ModificadaAlta (7.8)0.31%—Devolutions Remote Desktop Manager6/12/202317/6/2026
Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.
ModificadaAlta (7.8)4.3%💥 PoCAsana Desktop28/11/202317/6/2026
Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.
ModificadaAlta (7.8)0.26%—Autodesk Desktop Connector22/11/202317/6/2026
A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have elevated privileges leading to a Privilege Escalation vulnerability.
ModificadaMedia (6.5)0.65%—Zoom MeetingsZoom Virtual Desktop InfrastructureZoom15/11/202317/6/2026
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.
ModificadaAlta (8.8)0.66%—Zoom MeetingsZoom RoomsZoom Virtual Desktop InfrastructureZoom15/11/202317/6/2026
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
ModificadaAlta (7.5)1.1%—Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom Virtual Desktop Infrastructure+114/11/202317/6/2026
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
ModificadaMedia (6.5)0.85%—Zoom MeetingsZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom14/11/202317/6/2026
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (7.5)1.1%—Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom Virtual Desktop Infrastructure+114/11/202317/6/2026
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
ModificadaAlta (7.5)0.93%—Zoom Virtual Desktop InfrastructureZoom14/11/202317/6/2026
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.
ModificadaMedia (5.5)0.21%—Zoom RoomsZoom Virtual Desktop Infrastructure14/11/202317/6/2026
Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.
ModificadaMedia (6.5)0.62%—Zoom MeetingsZoom RoomsZoom Virtual Desktop InfrastructureZoom14/11/202317/6/2026
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.
ModificadaAlta (8.8)3.3%—Zohocorp Manageengine Desktop Central3/11/202317/6/2026
A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests.
ModificadaMedia (6.1)2.9%—Zohocorp Manageengine Desktop Central3/11/202317/6/2026
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf.
ModificadaMedia (6.1)2.9%—Zohocorp Manageengine Desktop Central3/11/202317/6/2026
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.
ModificadaBaja (3.3)0.19%—Mattermost Desktop2/11/202317/6/2026
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.
ModificadaMedia (5.3)0.49%—Mattermost Desktop2/11/202317/6/2026
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
ModificadaMedia (5.3)0.33%—Mattermost Desktop2/11/202317/6/2026
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
ModificadaCrítica (9.8)0.58%—Devolutions Remote Desktop Manager1/11/202317/6/2026
A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.