Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.61%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+119/6/202623/7/2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
ModificadaAlta (8.8)0.82%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+119/6/202623/7/2026
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
ModificadaAlta (7.5)0.47%—Microsoft Remote Desktop ClientMicrosoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+39/6/202623/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
ModificadaAlta (7.5)0.47%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+119/6/202623/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AplazadaCrítica (10)0.52%—Remotespark SparkviewAI29/5/202621/7/2026
Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection. Depending on implementation, the vulnerability can be exploited by an unauthenticated…
Pendiente de análisisMedia (4)0.15%—HCL Bigfix Remote Control ServerAI27/5/202617/6/2026
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.
AplazadaCrítica (10)0.55%—Remote Spark SparkviewAI8/5/202617/6/2026
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker.
Pendiente de análisisMedia (5.9)0.38%—Amazon X-ray Remote SamplerAIOpentelemetry Sampler AWSAI23/4/202617/6/2026
The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0.1.0-alpha.8, OpenTelemetry.Sampler.AWS reads unbounded HTTP response bodies from a configured AWS X-Ray remote sampling endpoint into memory. AWSXRaySamplerClient.DoRequestAsync called…
AnalizadaAlta (7)0.33%—Openremote22/4/202617/6/2026
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler uses the `{realm}` path segment when talking to the identity provider…
AnalizadaAlta (7.6)0.36%—Openremote22/4/202617/6/2026
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user who can call the import endpoint may trigger XML external entity processing, which can lead to server-side file disclosure…
AnalizadaCrítica (9.9)0.91%—Openremote15/4/202617/6/2026
OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-supplied scripts via Nashorn's ScriptEngine.eval() without sandboxing,…
AnalizadaAlta (8.8)0.82%—Microsoft Remote Desktop ClientMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1114/4/202625/9/2026
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AplazadaMedia (6.9)0.15%—Remote Process ExplorerAI5/4/202624/7/2026
Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the added computer,…
Pendiente de análisisCrítica (9.3)0.58%—Remote Spectrum Monitor Ms27102aAI31/3/202624/7/2026
The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design rather than a deployment error.
Pendiente de análisisMedia (4.9)0.49%—Integrated Dell Remote Access Controller 9AI18/3/202617/6/2026
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability,…
Pendiente de análisisMedia (5.3)0.28%—Integrated Dell Remote Access Controller 9AIIntegrated Dell Remote Access Controller 10AI18/3/202617/6/2026
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability. A high privileged attacker with adjacent network access could…
ModificadaCrítica (9.8)0.50%—Devolutions Remote Desktop Manager3/3/202617/6/2026
Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information to other users, by creating or editing…
AnalizadaAlta (7.1)0.26%—Vivo Smartremote Module27/2/202617/6/2026
The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.
AplazadaAlta (8.6)1.5%—Saturn Remote Mouse ServerAI18/2/202617/6/2026
Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards…
AplazadaAlta (8.8)0.61%—Next-mdx-remoteAI12/2/202617/6/2026
The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-2026-0969, is fixed in next-mdx-remote 6.0.0.
AplazadaAlta (8.5)0.16%—Zilab Remote Console ServerAI11/2/202617/6/2026
Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be run with…
AnalizadaCrítica (9.9)91%⚠ Explotación activaBeyondtrust Privileged Remote AccessBeyondtrust Remote Support6/2/202617/6/2026
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site…
AplazadaAlta (8.4)0.39%—Remote Desktop AuditAI3/2/202617/6/2026
Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wizard file import process. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) bypass and execute shellcode when importing computer…
AplazadaCrítica (9.3)0.93%—Unifiedremote Unified RemoteAI23/1/202617/6/2026
Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary commands. Attackers can exploit the service by connecting to port 9512 and sending specially crafted packets to open a command prompt and download and execute malicious…
AnalizadaAlta (8.5)0.23%—Remotemouse Remote Mouse16/1/202617/6/2026
Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the RemoteMouseService to inject malicious executables and gain administrative access.