Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
3979 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.68% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder structure, and add new files. Users should… | |
| Modificada | Media (6.5) | 1.1% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can recover and modify the contents of end-to-end encrypted files. Users should upgrade the Nextcloud Desktop client to 3.6.5 to receive a patch.… | |
| Modificada | Media (6.5) | 0.48% | — | Devolutions Remote Desktop Manager | 2/4/2023 | 17/6/2026 | Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive information via the error message dialog that displays the password in clear text. | |
| Modificada | Media (6.5) | 0.44% | — | Devolutions Remote Desktop Manager | 2/4/2023 | 17/6/2026 | Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision. | |
| Modificada | Alta (7.5) | 0.53% | — | Zoom RoomsZoomZoom Virtual Desktop Infrastructure | 27/3/2023 | 17/6/2026 | Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond… | |
| Modificada | Alta (7.8) | 0.90% | — | X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+14 | 27/3/2023 | 17/6/2026 | A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote… | |
| Modificada | Alta (7.5) | 0.98% | — | Zoom RoomsZoom Virtual Desktop InfrastructureZoom | 16/3/2023 | 17/6/2026 | Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, transmitted text to Microsoft’s… | |
| Modificada | Alta (7.1) | 0.22% | — | Docker Desktop | 13/3/2023 | 17/6/2026 | Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to docker.raw.sock, or npipe:////.pipe/docker_engine_linux on Windows, via the -H (--host) CLI flag or the DOCKER_HOST environment variable and launch containers without the… | |
| Modificada | Alta (7.8) | 0.27% | — | Docker Desktop | 13/3/2023 | 17/6/2026 | Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL. | |
| Modificada | Media (6.5) | 1.1% | — | Devolutions Remote Desktop Manager | 10/3/2023 | 17/6/2026 | Improper removal of sensitive data in the entry edit feature of Hub Business submodule in Devolutions Remote Desktop Manager PowerShell Module 2022.3.1.5 and earlier allows an authenticated user to access sensitive data on entries that were edited using the affected submodule. | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa | WebkitgtkWpewebkit WPE WebkitRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUS+19 | 6/3/2023 | 8/10/2026 | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues. | |
| Modificada | Media (5.5) | 0.37% | — | Fabulatech Webcam FOR Remote Desktop | 6/3/2023 | 17/6/2026 | A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42. It has been classified as problematic. Affected is the function 0x222018 in the library ftwebcam.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has… | |
| Modificada | Media (5.5) | 0.37% | — | Fabulatech Webcam FOR Remote Desktop | 6/3/2023 | 17/6/2026 | A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This issue affects some unknown processing in the library ftwebcam.sys of the component Global Variable Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host.… | |
| Modificada | Media (5.5) | 0.37% | — | Fabulatech Webcam FOR Remote Desktop | 6/3/2023 | 17/6/2026 | A vulnerability has been found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This vulnerability affects the function 0x222010/0x222018 in the library ftwebcam.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The… | |
| Modificada | Alta (8.8) | 8.7% | — | Zohocorp Manageengine Desktop Central | 25/2/2023 | 17/6/2026 | Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting… | |
| Modificada | Alta (7.8) | 0.27% | — | Citrix Virtual Apps AND Desktops | 16/2/2023 | 17/6/2026 | A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA. | |
| Modificada | Alta (7.4) | 0.68% | — | Fujitsu Tsclinical Define.xml GeneratorFujitsu Tsclinical Metadata Desktop Tools | 15/2/2023 | 17/6/2026 | Existe una restricción inadecuada de la vulnerabilidad de referencia de entidad externa XML (XXE) en tsClinical Define.xml Generator todas las versiones (v1.0.0 a v1.4.0) y tsClinical Metadata Desktop Tools versión 1.0.3 a versión 1.1.0. Si se aprovecha esta vulnerabilidad, un atacante puede obtener un archivo… | |
| Modificada | Alta (7.8) | 0.31% | — | Genymotion Desktop | 13/2/2023 | 17/6/2026 | Se descubrió que Genymotion Desktop v3.3.2 contiene una vulnerabilidad de secuestro de DLL que permite a los atacantes escalar privilegios y ejecutar código arbitrario a través de una DLL manipulada. | |
| Modificada | Alta (7) | 0.14% | — | HP 348 G4 FirmwareHP 260 G2 Desktop Mini FirmwareHP 218 PRO G5 MT FirmwareHP 260 G3 Desktop Mini Firmware+21 | 12/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability. | |
| Modificada | Media (6.1) | 0.68% | — | Nextcloud Desktop | 6/2/2023 | 17/6/2026 | Nextcloud Desktop Client es una herramienta para sincronizar archivos desde un servidor Nextcloud con su computadora. A las versiones anteriores a la 3.6.3 les falta desinfección en las etiquetas qml que se utilizan para elementos HTML básicos como las líneas `strong`, `em` y `head` en la interfaz de usuario del… | |
| Modificada | Alta (8.8) | 0.95% | — | Fedoraproject SssdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+9 | 1/2/2023 | 17/6/2026 | sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters | |
| Modificada | Alta (7) | 0.14% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+313 | 1/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.8) | 0.31% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 1/2/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.24% | — | HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+177 | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.24% | — | HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+177 | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities. |