Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
5105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.64% | — | Uvdesk Community SkeletonAI | 16/9/2026 | 22/9/2026 | UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control… | |
| Pendiente de análisis | Alta (7.7) | 0.34% | — | Oracle WEB Applications Desktop IntegratorAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Web Applications… | |
| Pendiente de análisis | Media (6.5) | 0.34% | — | Oracle WEB Applications Desktop IntegratorAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications… | |
| Pendiente de análisis | Media (5.1) | 0.18% | — | Newell Brands Dymo Connect DesktopAI | 15/9/2026 | 22/9/2026 | The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension… | |
| Pendiente de análisis | Crítica (9.4) | 0.20% | — | Apple MacosAIDocker DesktopAI | 15/9/2026 | 16/9/2026 | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host… | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Parallels DesktopAI | 14/9/2026 | 18/9/2026 | Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon… | |
| Aplazada | Alta (8.4) | 0.18% | — | Rakuten Kobo Desktop ApplicationAI | 14/9/2026 | 16/9/2026 | The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation. | |
| Aplazada | Alta (8.6) | 0.19% | — | Autodesk Fusion DesktopAI | 10/9/2026 | 11/9/2026 | A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing… | |
| Analizada | Alta (7.5) | 0.64% | — | Microsoft Remote Desktop Client | 8/9/2026 | 16/9/2026 | Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7) | 0.28% | — | Microsoft Power Automate FOR Desktop | 8/9/2026 | 29/9/2026 | Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Alta (8.6) | 0.17% | — | Bilibili DesktopAI | 5/9/2026 | 23/9/2026 | Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the… | |
| Aplazada | Media (6.9) | 0.41% | — | Lightstar Smartit Desktop ManagerAILightstar Smartit AgentAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts. | |
| Aplazada | Alta (8.7) | 0.33% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code. | |
| Pendiente de análisis | Alta (7.5) | 0.37% | — | Cisco Desk Phone 9800 SeriesAICisco IP Phone 7800 SeriesAICisco IP Phone 8800 SeriesAICisco Video Phone 8875AI+1 | 2/9/2026 | 2/9/2026 | A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is… | |
| Pendiente de análisis | Media (5.5) | 0.11% | — | Autodesk ProductsAI | 2/9/2026 | 3/9/2026 | A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially… | |
| En análisis | Crítica (9.8) | 0.37% | — | Openai Codex DesktopAIGITAI | 1/9/2026 | 2/9/2026 | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an… | |
| En análisis | Alta (7.3) | 0.11% | — | Openai Codex CLIAIOpenai Codex DesktopAIGit-scm GITAI | 1/9/2026 | 2/9/2026 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-local core.fsmonitor setting. If a user opens or uses an attacker-prepared repository whose preserved .git/config sets core.fsmonitor to an… | |
| En análisis | Alta (8.8) | 0.30% | — | Openai Codex CLIAIOpenai Codex DesktopAIMicrosoft PowershellAI | 1/9/2026 | 2/9/2026 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex… | |
| En análisis | Alta (7.3) | 0.11% | — | Openai Codex DesktopAI | 1/9/2026 | 3/9/2026 | OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can… | |
| Aplazada | Crítica (9.8) | 0.93% | — | Bilibili DesktopAI | 27/8/2026 | 1/9/2026 | An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components. |