Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.30%—KDE Plasma-workspace5/7/202417/6/2026
KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local connections are accepted. This allows another user on the same machine to gain access to the session manager, e.g., use the session-restore feature to…
AplazadaMedia (6.8)0.36%—Vmware Workspace ONE UEMAI27/6/202417/6/2026
VMware Workspace One UEM update addresses an information exposure vulnerability. A malicious actor with network access to the Workspace One UEM may be able to perform an attack resulting in an information exposure.
AnalizadaMedia (6.3)0.40%—Devolutions Workspace7/3/202417/6/2026
Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions
ModificadaBaja (3.7)0.79%—KDE Plasma-workspace11/2/202417/6/2026
A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file components/calendar/eventpluginsmanager.cpp of the component Theme File Handler. The manipulation of the argument pluginId leads to path…
ModificadaMedia (4.6)0.40%—Vmware Workspace ONE Launcher12/12/202317/6/2026
Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information.
ModificadaMedia (6.5)0.59%—Devolutions Workspace7/12/202317/6/2026
Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.
ModificadaMedia (6.1)0.40%—Vmware Workspace ONE UEM31/10/202317/6/2026
VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and retrieve their SAML response to login as the victim user.
ModificadaAlta (7.6)0.55%—Oracle Hyperion Workspace18/7/202317/6/2026
Vulnerability in the Oracle Hyperion Workspace product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Workspace. Successful attacks…
ModificadaMedia (5.5)0.18%—Citrix Workspace10/7/202317/6/2026
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched.
ModificadaMedia (5.4)0.37%—Palantir Foundry Workspace-server29/6/202317/6/2026
A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a limited capacity. A fix was deployed with…
ModificadaMedia (6.1)0.35%—Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector30/5/202317/6/2026
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
ModificadaAlta (7.8)0.18%—Devolutions Workspace24/4/202317/6/2026
Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub Business space without being prompted to enter the password via an unimplemented "Force Login" security feature. This…
ModificadaMedia (6.8)0.92%—Vmware Workspace ONE Content28/2/202317/6/2026
VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode.
ModificadaAlta (7.8)0.22%—Citrix Workspace16/2/202317/6/2026
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
ModificadaMedia (5.5)0.26%—Citrix Workspace16/2/202317/6/2026
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
ModificadaMedia (5.4)0.58%—Onlyoffice Workspace7/2/202317/6/2026
Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition.
ModificadaCrítica (9.8)0.88%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.
ModificadaMedia (6.1)0.46%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
ModificadaCrítica (9.8)0.88%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
ModificadaCrítica (9.8)0.99%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
ModificadaCrítica (9.8)1.0%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
ModificadaBaja (3.3)0.20%—IBM Planning Analytics Workspace8/9/202217/6/2026
IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 217371.
ModificadaAlta (7.5)17%—Checkpoint Capsule Workspace18/7/202217/6/2026
A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). This could result in application crashing but could not be used to gather any sensitive information.
ModificadaMedia (6.1)0.57%—Siemens Teamcenter Active Workspace14/6/202217/6/2026
A vulnerability has been identified in Teamcenter Active Workspace V5.2 (All versions < V5.2.9), Teamcenter Active Workspace V6.0 (All versions < V6.0.3). A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the affected application that could allow an attacker to execute malicious code…
ModificadaAlta (7.8)2.4%—Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Vrealize Suite Lifecycle Manager20/5/202217/6/2026
VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
Orbitaley — Vulnerabilidades