Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.61% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (7.5) | 0.47% | — | Microsoft Remote Desktop ClientMicrosoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+3 | 9/6/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (7.5) | 0.47% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Crítica (10) | 0.52% | — | Remotespark SparkviewAI | 29/5/2026 | 21/7/2026 | Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection. Depending on implementation, the vulnerability can be exploited by an unauthenticated… | |
| Pendiente de análisis | Media (4) | 0.15% | — | HCL Bigfix Remote Control ServerAI | 27/5/2026 | 17/6/2026 | A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources. | |
| Aplazada | Crítica (10) | 0.55% | — | Remote Spark SparkviewAI | 8/5/2026 | 17/6/2026 | A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker. | |
| Pendiente de análisis | Media (5.9) | 0.38% | — | Amazon X-ray Remote SamplerAIOpentelemetry Sampler AWSAI | 23/4/2026 | 17/6/2026 | The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0.1.0-alpha.8, OpenTelemetry.Sampler.AWS reads unbounded HTTP response bodies from a configured AWS X-Ray remote sampling endpoint into memory. AWSXRaySamplerClient.DoRequestAsync called… | |
| Analizada | Alta (7) | 0.33% | — | Openremote | 22/4/2026 | 17/6/2026 | OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler uses the `{realm}` path segment when talking to the identity provider… | |
| Analizada | Alta (7.6) | 0.36% | — | Openremote | 22/4/2026 | 17/6/2026 | OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user who can call the import endpoint may trigger XML external entity processing, which can lead to server-side file disclosure… | |
| Analizada | Crítica (9.9) | 0.91% | — | Openremote | 15/4/2026 | 17/6/2026 | OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-supplied scripts via Nashorn's ScriptEngine.eval() without sandboxing,… | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 14/4/2026 | 25/9/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (6.9) | 0.15% | — | Remote Process ExplorerAI | 5/4/2026 | 24/7/2026 | Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the added computer,… | |
| Pendiente de análisis | Crítica (9.3) | 0.58% | — | Remote Spectrum Monitor Ms27102aAI | 31/3/2026 | 24/7/2026 | The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design rather than a deployment error. | |
| Pendiente de análisis | Media (4.9) | 0.49% | — | Integrated Dell Remote Access Controller 9AI | 18/3/2026 | 17/6/2026 | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability,… | |
| Pendiente de análisis | Media (5.3) | 0.28% | — | Integrated Dell Remote Access Controller 9AIIntegrated Dell Remote Access Controller 10AI | 18/3/2026 | 17/6/2026 | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability. A high privileged attacker with adjacent network access could… | |
| Modificada | Crítica (9.8) | 0.50% | — | Devolutions Remote Desktop Manager | 3/3/2026 | 17/6/2026 | Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information to other users, by creating or editing… | |
| Analizada | Alta (7.1) | 0.26% | — | Vivo Smartremote Module | 27/2/2026 | 17/6/2026 | The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage. | |
| Aplazada | Alta (8.6) | 1.5% | — | Saturn Remote Mouse ServerAI | 18/2/2026 | 17/6/2026 | Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards… | |
| Aplazada | Alta (8.8) | 0.61% | — | Next-mdx-remoteAI | 12/2/2026 | 17/6/2026 | The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-2026-0969, is fixed in next-mdx-remote 6.0.0. | |
| Aplazada | Alta (8.5) | 0.16% | — | Zilab Remote Console ServerAI | 11/2/2026 | 17/6/2026 | Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be run with… | |
| Analizada | Crítica (9.9) | 91% | ⚠ Explotación activa | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 6/2/2026 | 17/6/2026 | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site… | |
| Aplazada | Alta (8.4) | 0.39% | — | Remote Desktop AuditAI | 3/2/2026 | 17/6/2026 | Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wizard file import process. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) bypass and execute shellcode when importing computer… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Unifiedremote Unified RemoteAI | 23/1/2026 | 17/6/2026 | Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary commands. Attackers can exploit the service by connecting to port 9512 and sending specially crafted packets to open a command prompt and download and execute malicious… | |
| Analizada | Alta (8.5) | 0.23% | — | Remotemouse Remote Mouse | 16/1/2026 | 17/6/2026 | Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the RemoteMouseService to inject malicious executables and gain administrative access. |