Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
3979 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.20% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Media (6.5) | 1.4% | — | Freedesktop DbusFedoraproject FedoraDebian Linux | 8/6/2023 | 17/6/2026 | D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a… | |
| Modificada | Media (5.5) | 0.36% | — | Fabulatech USB FOR Remote Desktop | 24/5/2023 | 17/6/2026 | A vulnerability was found in FabulaTech USB for Remote Desktop 6.1.0.0. It has been rated as problematic. Affected by this issue is the function 0x220448/0x220420/0x22040c/0x220408 of the component IoControlCode Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The… | |
| Analizada | Media (5.3) | 1.2% | — | Microsoft Remote Desktop APP | 9/5/2023 | 17/6/2026 | Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability | |
| Modificada | Crítica (9.8) | 22% | 💥 Exploit | Appium-desktop | 2/5/2023 | 17/6/2026 | OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4. | |
| Modificada | Media (5.4) | 0.36% | — | Mattermost Desktop | 2/5/2023 | 17/6/2026 | Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website | |
| Modificada | Media (6.3) | 0.29% | — | Docker Desktop | 27/4/2023 | 17/6/2026 | Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerStartRequest class. This allows exploiting a symlink vulnerability in… | |
| Modificada | Alta (7.8) | 0.30% | — | Docker Desktop | 27/4/2023 | 17/6/2026 | Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation. | |
| Modificada | Alta (7.1) | 0.34% | — | Docker Desktop | 27/4/2023 | 17/6/2026 | Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder parameter for DockerDesktop.vhdx, a similar issue to CVE-2022-31647. | |
| Modificada | Alta (7.1) | 0.33% | — | Docker Desktop | 27/4/2023 | 17/6/2026 | Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659. | |
| Modificada | Media (6.5) | 0.42% | — | Devolutions Remote Desktop Manager | 25/4/2023 | 17/6/2026 | Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector. | |
| Modificada | Media (6.1) | 0.19% | — | Pingidentity Desktop | 25/4/2023 | 17/6/2026 | PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted before the time-based lockout is activated. | |
| Modificada | Media (5.5) | 0.08% | — | UI Desktop | 19/4/2023 | 17/6/2026 | Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with access to UI Desktop configuration files to decrypt their content.This vulnerability is fixed in Version 0.62.3 and later. | |
| Modificada | Media (5.5) | 0.16% | — | UI Desktop | 19/4/2023 | 17/6/2026 | A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VPN credentials while UID VPN is starting.This vulnerability is fixed in Version 0.62.3 and later. | |
| Modificada | Alta (7.8) | 0.16% | — | UI Desktop | 19/4/2023 | 17/6/2026 | A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a malicious actor with local access to a Windows device running said application to submit arbitrary commands as SYSTEM.This vulnerability is fixed in Version 0.62.3 and later. | |
| Modificada | Crítica (9.8) | 1.9% | — | Nanoleaf Desktop | 18/4/2023 | 9/7/2026 | Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request. | |
| Analizada | Media (6.5) | 2.1% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+10 | 11/4/2023 | 17/6/2026 | Remote Desktop Protocol Client Information Disclosure Vulnerability | |
| Modificada | Media (6.5) | 0.52% | — | Devolutions Remote Desktop Manager | 11/4/2023 | 17/6/2026 | Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factor authentication via the application user interface and open entries. | |
| Modificada | Media (4.3) | 0.40% | — | Devolutions Remote Desktop Manager | 11/4/2023 | 17/6/2026 | No access control for the OTP key on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface. | |
| Modificada | Alta (7.5) | 0.55% | — | Docker Desktop | 6/4/2023 | 17/6/2026 | In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information. Only users who have Access Experimental Features enabled and have logged in to a… | |
| Modificada | Media (6.5) | 0.39% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a malicious server could get the desktop client to encrypt files with a key known to… | |
| Modificada | Media (6.4) | 0.68% | — | Nextcloud DesktopNextcloud | 4/4/2023 | 17/6/2026 | Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder… |