Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.37% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Service Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to… | |
| Modificada | Crítica (10) | 1.2% | — | Parallels Remote Application Server | 14/12/2023 | 17/6/2026 | The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques. | |
| Modificada | Alta (8.1) | 2.1% | — | Parallels Remote Application Server | 23/11/2022 | 17/6/2026 | The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header. | |
| Modificada | Alta (7.8) | 0.34% | — | Parallels Access | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Desktop Control… | |
| Modificada | Alta (7.8) | 0.34% | — | Parallels Access | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Parallels… | |
| Modificada | Alta (7.8) | 0.42% | — | Parallels Access | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39313) Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Dispatcher… | |
| Modificada | Alta (7.8) | 0.24% | — | Parallels Access | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Parallels… | |
| Modificada | Alta (7.8) | 0.26% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the update… | |
| Modificada | Alta (7.8) | 0.30% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the update… | |
| Modificada | Alta (8.8) | 0.34% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (8.2) | 0.35% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the ACPI virtual… | |
| Modificada | Alta (8.2) | 0.34% | — | Parallels Desktop | 15/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (49187). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the HDAudio… | |
| Modificada | Alta (7.8) | 0.27% | — | Parallels Desktop | 15/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Parallels Service. By… | |
| Modificada | Media (6.1) | 2.3% | — | Parallels H-sphere | 16/5/2022 | 17/6/2026 | Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter. | |
| Modificada | Alta (8.8) | 0.42% | — | Parallels | 25/1/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate… | |
| Modificada | Alta (8.8) | 0.42% | — | Parallels | 25/1/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate… | |
| Modificada | Alta (8.2) | 0.43% | — | Parallels | 25/1/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate… | |
| Modificada | Alta (7.1) | 0.27% | — | Parallels Remote Application Server | 17/12/2021 | 17/6/2026 | Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confidentiality, availability and integrity of the information of the user could be compromised if an attacker is able to… | |
| Modificada | Alta (8.8) | 0.24% | — | Parallels Desktop | 25/10/2021 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the WinAppHelper… | |
| Modificada | Alta (8.8) | 0.27% | — | Parallels Desktop | 25/10/2021 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate… | |
| Modificada | Alta (8.8) | 0.27% | — | Parallels Desktop | 25/10/2021 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the virtio-gpu… | |
| Modificada | Media (6.5) | 0.27% | — | Parallels Desktop | 25/10/2021 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (7.8) | 0.25% | — | Parallels Desktop | 25/10/2021 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate… | |
| Modificada | Media (6) | 0.45% | — | Parallels Desktop | 29/4/2021 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the IDE… | |
| Modificada | Media (6) | 0.45% | — | Parallels Desktop | 29/4/2021 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the IDE… |