Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.38% | — | Ivanti Workspace Control | 10/6/2025 | 17/6/2026 | A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials. | |
| Aplazada | Crítica (9.9) | 0.77% | — | Wildermyth WilderforgeAIWildermyth ExamplemodAIWildermyth WilderworkspaceAIWildermythgameproviderAI+5 | 9/6/2025 | 17/6/2026 | WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage of `${{ github.event.review.body }}` and other user controlled variables directly inside shell script contexts in GitHub Actions… | |
| Analizada | Crítica (9.8) | 0.38% | — | Onevision Workspace | 28/4/2025 | 17/6/2026 | OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution. | |
| Aplazada | Alta (7.2) | 0.16% | — | Philips Intellispace PortalAIPhilips Advanced Visualization WorkspaceAI | 7/4/2025 | 17/6/2026 | We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. As a result, attackers can reverse-engineer the application to… | |
| Aplazada | Alta (7.7) | 0.46% | — | Amazon WorkspacesAI | 15/1/2025 | 17/6/2026 | An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle. | |
| Aplazada | Alta (7.7) | 0.51% | — | Amazon WorkspacesAIAmazon Appstream 2.0AIAmazon DCV ClientsAI | 15/1/2025 | 17/6/2026 | An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle. | |
| Analizada | Alta (7.8) | 0.21% | — | Ivanti Workspace Control | 11/12/2024 | 17/6/2026 | Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation. | |
| Analizada | Media (4.8) | 0.14% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption. | |
| Analizada | Alta (7.3) | 0.28% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges. | |
| Analizada | Alta (7.5) | 0.39% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors. | |
| Analizada | Alta (8.1) | 0.45% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request. | |
| Analizada | Crítica (9.8) | 0.46% | — | Cybelesoft Thinfinity Workspace | 13/11/2024 | 17/6/2026 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established. | |
| Analizada | Media (5.4) | 0.18% | — | Citrix Workspace | 11/9/2024 | 17/6/2026 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | |
| Analizada | Alta (7) | 0.25% | — | Citrix Workspace | 11/9/2024 | 17/6/2026 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | |
| Modificada | Alta (7.8) | 0.27% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. | |
| Modificada | Alta (7.8) | 0.27% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.24% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. | |
| Modificada | Alta (7.8) | 0.16% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS credentials. | |
| Modificada | Alta (7.8) | 0.24% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. | |
| Modificada | Alta (7.8) | 0.24% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Alta (7.1) | 0.15% | — | Citrix Workspace | 10/9/2024 | 17/6/2026 | Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to… | |
| Analizada | Crítica (9.1) | 0.43% | — | IBM Planning Analytics WorkspaceIBM Planning Analytics Local | 4/8/2024 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 292420. | |
| Analizada | Alta (8.5) | 0.39% | — | Citrix Workspace | 10/7/2024 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | |
| Analizada | Media (4.8) | 0.22% | — | Citrix Workspace | 10/7/2024 | 17/6/2026 | Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5 | |
| Modificada | Media (5.3) | 0.40% | — | Citrix Workspace | 10/7/2024 | 17/6/2026 | Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5 |