Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Horizontcms Project Horizontcms | 24/2/2022 | 17/6/2026 | HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/. | |
| Modificada | Media (6.5) | 0.36% | — | Vmware WorkstationVmware Horizon | 28/1/2022 | 17/6/2026 | VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual machine or remote desktop may exploit this issue to trigger a… | |
| Modificada | Media (5.4) | 0.91% | — | Opennms HorizonOpennms Meridian | 25/5/2021 | 17/6/2026 | In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site Scripting, since the function `add()`… | |
| Modificada | Media (5.4) | 1.0% | — | Opennms HorizonOpennms Meridian | 25/5/2021 | 17/6/2026 | In OpenNMS Horizon, versions opennms-18.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site Scripting, since the function… | |
| Modificada | Media (6.5) | 0.45% | — | Vmware WorkstationVmware Horizon Client | 24/5/2021 | 17/6/2026 | VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information… | |
| Modificada | Media (6.5) | 0.45% | — | Vmware WorkstationVmware Horizon Client | 24/5/2021 | 17/6/2026 | VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (JPEG2000 Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information… | |
| Modificada | Media (6.5) | 0.56% | — | Vmware WorkstationVmware Horizon Client | 24/5/2021 | 17/6/2026 | VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information… | |
| Modificada | Media (4.8) | 1.0% | — | Opennms HorizonOpennms Meridian | 20/5/2021 | 17/6/2026 | In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting, since the function… | |
| Modificada | Alta (8.8) | 0.73% | — | Opennms HorizonOpennms Meridian | 20/5/2021 | 17/6/2026 | In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no CSRF protection at… | |
| Modificada | Media (4.8) | 1.0% | — | Opennms HorizonOpennms Meridian | 20/5/2021 | 17/6/2026 | In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting since there is no validation… | |
| Modificada | Media (4.3) | 0.63% | — | Opennms HorizonOpennms Meridian | 20/5/2021 | 17/6/2026 | In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no CSRF protection, and since there is no… | |
| Modificada | Alta (8.8) | 2.4% | — | Opennms HorizonOpennms MeridianOpennms Newts | 17/2/2021 | 17/6/2026 | OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions. | |
| Modificada | Media (6.1) | 1.4% | — | Openstack HorizonDebian Linux | 4/12/2020 | 17/6/2026 | An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL. | |
| Modificada | Alta (8.8) | 2.5% | — | Horizontcms Project Horizontcms | 16/11/2020 | 17/6/2026 | An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name> | |
| Modificada | Alta (8.8) | 18% | 💥 Exploit | Horizontcms Project Horizontcms | 5/11/2020 | 17/6/2026 | An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on… | |
| Modificada | Media (6.5) | 1.3% | — | Vmware Horizon Client | 23/10/2020 | 17/6/2026 | VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges on the machine where Horizon Client for Windows is installed may be able to retrieve hashed credentials if the client crashes. | |
| Modificada | Media (5.4) | 0.67% | — | Vmware Horizon | 23/10/2020 | 17/6/2026 | VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which will be executed. | |
| Modificada | Alta (7.1) | 0.34% | — | Vmware Horizon Client | 16/10/2020 | 17/6/2026 | VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system access control issue during install time. Successful exploitation of this issue may allow an attacker to overwrite certain admin privileged files through a symbolic link attack at install time. This… | |
| Modificada | Media (6.5) | 0.96% | — | Vmware Horizon Daas | 22/9/2020 | 17/6/2026 | VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process. In order to exploit this issue, an… | |
| Modificada | Media (6.5) | 0.32% | — | Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO | 16/9/2020 | 17/6/2026 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerability due to an integer overflow issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to leak memory from TPView process… | |
| Modificada | Baja (3.3) | 0.29% | — | Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO | 16/9/2020 | 17/6/2026 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability due to an out-of-bounds write issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to create a partial denial-of-service… | |
| Modificada | Media (6.1) | 0.30% | — | Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO | 16/9/2020 | 17/6/2026 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (JPEG2000 parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to… | |
| Modificada | Media (6.1) | 0.30% | — | Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO | 16/9/2020 | 17/6/2026 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service… | |
| Modificada | Media (6.1) | 0.30% | — | Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO | 16/9/2020 | 17/6/2026 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMF Parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak… | |
| Modificada | Alta (7.8) | 0.37% | — | Vmware FusionVmware Horizon ClientVmware Remote Console | 10/7/2020 | 17/6/2026 | VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user… |