Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
5105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.15% | — | Autodesk Installer | 12/8/2026 | 4/9/2026 | A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability. | |
| Aplazada | Media (5.3) | 0.34% | — | Order Sync With Zendesk FOR WoocommerceAI | 12/8/2026 | 26/8/2026 | The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer… | |
| Pendiente de análisis | Alta (7.7) | 0.63% | — | Docker DesktopAIMicrosoft DEV Containers CLIAIAnysphere CursorAI | 11/8/2026 | 9/9/2026 | Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home… | |
| Aplazada | Alta (8.1) | 0.35% | — | Badchoice HandeskAI | 11/8/2026 | 28/8/2026 | A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to other teams via the TicketsController@update endpoint. The endpoint calls no authorize() method and performs no team-scoped ownership check. An attacker with any agent… | |
| Aplazada | Alta (8.1) | 0.35% | — | Badchoice HandeskAI | 11/8/2026 | 28/8/2026 | A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging to other teams via the LeadsController@update endpoint. The endpoint performs no authorization check, and the Lead model has guarded set to an empty array making all columns… | |
| Aplazada | Media (6.5) | 0.37% | — | Ladybirdweb Faveo HelpdeskAI | 11/8/2026 | 3/9/2026 | A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership, enabling any authenticated user to access… | |
| Modificada | Alta (7.8) | 0.19% | — | Autodesk Revit | 6/8/2026 | 17/9/2026 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Pendiente de análisis | Alta (7.8) | 0.17% | 💥 PoC | Freedesktop Udisks2AI | 6/8/2026 | 8/9/2026 | A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary… | |
| Modificada | Alta (7.8) | 0.19% | — | Autodesk Revit | 6/8/2026 | 17/9/2026 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.19% | — | Autodesk Revit | 6/8/2026 | 17/9/2026 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.19% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+8 | 6/8/2026 | 18/9/2026 | A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Media (5.5) | 0.16% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+8 | 6/8/2026 | 18/9/2026 | A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service | |
| Aplazada | Alta (7.2) | 0.48% | — | Wpdesk ForminatorAI | 6/8/2026 | 12/8/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Alta (7.8) | 0.21% | — | Autodesk FBX Software Development KIT | 4/8/2026 | 4/9/2026 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.21% | — | Autodesk FBX Software Development KIT | 4/8/2026 | 4/9/2026 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Aplazada | Alta (8.1) | 0.38% | — | Chat ON Desk Order NotificationsAI | 1/8/2026 | 26/8/2026 | The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS… | |
| Pendiente de análisis | Alta (7.5) | 0.52% | — | Gnome Remote DesktopAIRedhat Enterprise LinuxAI | 31/7/2026 | 13/8/2026 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP… | |
| Aplazada | Media (6.5) | 0.34% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body. | |
| Aplazada | Media (6.5) | 0.37% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users. | |
| Aplazada | Alta (7.5) | 0.41% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users'… | |
| Aplazada | Media (4.3) | 0.25% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site. | |
| Aplazada | Media (6.5) | 0.37% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets. | |
| Analizada | Crítica (9.8) | 1.0% | — | Solarwinds WEB Help Desk | 30/7/2026 | 17/8/2026 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled. | |
| Analizada | Media (5.5) | 0.25% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. | |
| Analizada | Alta (7.1) | 0.26% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. |