Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 2.1% | — | Parallels Remote Application Server | 23/11/2022 | 17/6/2026 | The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header. | |
| Modificada | Alta (7.8) | 0.34% | — | Parallels Access | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Desktop Control… | |
| Modificada | Alta (7.8) | 0.34% | — | Parallels Access | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Parallels… | |
| Modificada | Alta (7.8) | 0.42% | — | Parallels Access | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39313) Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Dispatcher… | |
| Modificada | Alta (7.8) | 0.24% | — | Parallels Access | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Parallels… | |
| Modificada | Alta (7.8) | 0.26% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the update… | |
| Modificada | Alta (7.8) | 0.30% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the update… | |
| Modificada | Alta (8.8) | 0.34% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (8.2) | 0.35% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the ACPI virtual… | |
| Modificada | Alta (8.2) | 0.34% | — | Parallels Desktop | 15/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (49187). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the HDAudio… | |
| Modificada | Alta (7.8) | 0.27% | — | Parallels Desktop | 15/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Parallels Service. By… | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Parallels H-sphere | 16/5/2022 | 17/6/2026 | Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter. | |
| Modificada | Alta (8.8) | 0.42% | — | Parallels | 25/1/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate… | |
| Modificada | Alta (8.8) | 0.42% | — | Parallels | 25/1/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate… | |
| Modificada | Alta (8.2) | 0.43% | — | Parallels | 25/1/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate… | |
| Modificada | Alta (7.1) | 0.27% | — | Parallels Remote Application Server | 17/12/2021 | 17/6/2026 | Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confidentiality, availability and integrity of the information of the user could be compromised if an attacker is able to… | |
| Modificada | Alta (8.8) | 0.24% | — | Parallels Desktop | 25/10/2021 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the WinAppHelper… | |
| Modificada | Alta (8.8) | 0.27% | — | Parallels Desktop | 25/10/2021 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate… | |
| Modificada | Alta (8.8) | 0.27% | — | Parallels Desktop | 25/10/2021 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the virtio-gpu… | |
| Modificada | Media (6.5) | 0.27% | — | Parallels Desktop | 25/10/2021 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (7.8) | 0.25% | — | Parallels Desktop | 25/10/2021 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate… | |
| Modificada | Media (6) | 0.45% | — | Parallels Desktop | 29/4/2021 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the IDE… | |
| Modificada | Media (6) | 0.45% | — | Parallels Desktop | 29/4/2021 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the IDE… | |
| Modificada | Media (6) | 0.45% | — | Parallels Desktop | 29/4/2021 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the IDE… | |
| Modificada | Alta (8.2) | 0.44% | — | Parallels Desktop | 29/4/2021 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the IDE virtual… |