Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
5106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.18% | — | Autodesk Revit | 10/7/2025 | 17/6/2026 | A maliciously crafted RTE file, when parsed through Autodesk Revit, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.36% | — | Autodesk Revit | 10/7/2025 | 17/6/2026 | A maliciously crafted RFA, RTE, or RVT file, when parsed through Autodesk Revit, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.24% | 💥 PoC | Citrix Virtual Apps AND Desktops | 8/7/2025 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS | |
| Analizada | Crítica (9.6) | 1.1% | — | Adobe Connect Desktop Application | 8/7/2025 | 17/6/2026 | Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interaction and scope is changed. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 8/7/2025 | 17/6/2026 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (5.2) | 0.15% | — | Docker DesktopAI | 3/7/2025 | 17/6/2026 | System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain secrets and further use them to gain… | |
| Modificada | Media (5.5) | 0.45% | — | Freedesktop Poppler | 2/7/2025 | 17/6/2026 | Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue. | |
| Analizada | Alta (7.8) | 55% | ⚠ Explotación activa💥 Exploit | Sudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+4 | 30/6/2025 | 17/6/2026 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | |
| Aplazada | Alta (7) | 0.47% | 💥 PoC | LibblockdevAIFreedesktop UdisksAI | 19/6/2025 | 30/6/2026 | A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able… | |
| Modificada | Media (6.6) | 0.20% | — | Autodesk MayaAutodesk Universal Scene Description | 11/6/2025 | 17/6/2026 | A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption. | |
| Analizada | Media (6.5) | 1.4% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 10/6/2025 | 17/6/2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.8) | 0.21% | — | Autodesk Installer | 10/6/2025 | 17/6/2026 | A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may lead to code execution. | |
| Analizada | Crítica (9.8) | 1.2% | — | Microsoft Power Automate FOR Desktop | 5/6/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.1% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation. | |
| Analizada | Alta (7.8) | 0.32% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken, a root service writes to a file owned by a normal user. By using a hard link, an attacker can write to an arbitrary file, potentially… | |
| Analizada | Alta (7.8) | 0.28% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is deleted, a root service verifies and modifies the ownership of the snapshot files. By using a symlink, an attacker can change the ownership of… | |
| Analizada | Alta (7.8) | 0.32% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual machine is restored, the prl_vmarchiver tool decompresses the file and writes the content back to its original location using root… | |
| Modificada | Alta (7.8) | 0.20% | — | Autodesk Revit | 2/6/2025 | 17/6/2026 | A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Media (4.4) | 0.21% | — | Django-helpdesk Project Django-helpdesk | 31/5/2025 | 17/6/2026 | django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py. | |
| Analizada | Alta (7.5) | 0.57% | — | Devolutions Remote Desktop Manager | 29/5/2025 | 17/6/2026 | Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specific circumstances, entries may be unintentionally moved from user vaults to shared… | |
| Modificada | Alta (8.8) | 0.42% | — | Elula Wsdesk | 23/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system allows Upload a Web Shell to a Web Server.This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through <= 3.2.9. | |
| Aplazada | Alta (7.4) | 0.82% | — | Gnome-remote-desktopAI | 22/5/2025 | 30/6/2026 | A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files… | |
| Analizada | Media (6.5) | 1.6% | — | Zohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 22/5/2025 | 17/6/2026 | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded. | |
| Aplazada | Baja (3.3) | 0.17% | — | Github DesktopAIGITAI | 21/5/2025 | 17/6/2026 | GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file in a commit of their making in the history view can cause information disclosure by means of Git attempting to access a network share. This affects… | |
| Analizada | Media (6.1) | 0.18% | — | Nextcloud Desktop | 16/5/2025 | 17/6/2026 | Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes… |