Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
3978 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (7.5) | 0.47% | — | Microsoft Remote Desktop ClientMicrosoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+3 | 9/6/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (7.5) | 0.47% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Crítica (9.8) | 0.53% | — | Freedesktop Libinput | 4/6/2026 | 22/7/2026 | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution | |
| Aplazada | Baja (2.1) | 0.35% | — | Wonderwhy-er DesktopcommandermcpAI | 3/6/2026 | 22/7/2026 | A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a manipulation of the argument SearchResult[] results in inefficient regular expression complexity. It is possible to… | |
| Aplazada | Baja (2.1) | 0.22% | — | Wonderwhy-er DesktopcommandermcpAI | 3/6/2026 | 22/7/2026 | A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is… | |
| Pendiente de análisis | Alta (8.2) | 0.15% | — | Docker DesktopAI | 2/6/2026 | 22/7/2026 | Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry invalidation event. This issue has been fixed in Docker Desktop 4.76.0. | |
| Pendiente de análisis | Baja (2) | 0.13% | — | Strongdm Desktop ApplicationAIStrongdm Desktop ClientAIMicrosoft WindowsAI | 29/5/2026 | 6/10/2026 | StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS… | |
| Aplazada | Alta (7) | 0.12% | — | Soroush IM Desktop APPAI | 25/5/2026 | 23/7/2026 | Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unlock the client and… | |
| Analizada | Alta (8.8) | 0.18% | 💥 PoC | Docker Desktop | 22/5/2026 | 23/7/2026 | The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Python file, MLX-LM uses… | |
| Analizada | Alta (8.8) | 0.18% | 💥 PoC | Docker Desktop | 22/5/2026 | 23/7/2026 | The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model pulled from an OCI… | |
| Analizada | Alta (8.8) | 0.20% | — | Docker Desktop | 22/5/2026 | 23/7/2026 | The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the admin-settings configuration. However, the --use-api-socket flag adds the Docker socket mount via the… | |
| Analizada | Baja (3.5) | 0.29% | — | Mattermost Desktop | 18/5/2026 | 17/6/2026 | Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash the desktop client via invoking {{window.close()}} in the renderer context, leading to a denial of… | |
| Analizada | Media (6.5) | 0.33% | — | Mattermost Desktop | 18/5/2026 | 17/6/2026 | Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}. Mattermost Advisory ID: MMSA-2026-00618 | |
| Analizada | Crítica (9.1) | 0.35% | — | Freedesktop Gst-plugins-good | 14/5/2026 | 17/6/2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero. | |
| Analizada | Media (5.5) | 0.14% | — | Freedesktop Gst-plugins-good | 14/5/2026 | 17/6/2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero. | |
| Analizada | Alta (7.8) | 0.16% | — | Zoom Workplace Virtual Desktop Infrastructure | 13/5/2026 | 17/6/2026 | External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Alta (8.5) | 0.16% | — | Anthropic Claude Desktop | 13/5/2026 | 17/6/2026 | The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the CoworkVMService component in Claude Desktop for Windows ran as SYSTEM and did not validate whether the VM bundle directory was a real directory or an NTFS directory junction… | |
| Analizada | Alta (7.4) | 0.22% | — | Anthropic Claude Desktop | 13/5/2026 | 17/6/2026 | The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. From 1.2581.0 to before 1.4304.0, Claude Desktop's SSH remote development feature verified only whether a hostname existed in ~/.ssh/known_hosts without comparing the server's presented host key… | |
| Pendiente de análisis | Media (5.1) | 0.18% | — | Freedesktop MalcontentAI | 13/5/2026 | 17/6/2026 | The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-service.c in malcontent-timerd allows arbitrary users in the system to slowly fill up disk space in /var/lib/malcontent-timerd | |
| Pendiente de análisis | Alta (7) | 0.16% | — | KDE PlasmaAIFreedesktop DbusAI | 13/5/2026 | 17/6/2026 | The new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.aA compromised plasmalogin service account can chown() arbitrary files in the system. | |
| Analizada | Crítica (9.3) | 1.0% | — | Adobe Connect Desktop Application | 12/5/2026 | 28/8/2026 | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated… | |
| Analizada | Crítica (9.6) | 1.9% | — | Adobe Connect Desktop Application | 12/5/2026 | 28/8/2026 | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user… | |
| Analizada | Media (6.5) | 1.00% | — | Microsoft Power Automate FOR Desktop | 12/5/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.6) | 0.85% | — | Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile | 4/5/2026 | 17/6/2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note… |