Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the prl_hypervisor kext. The… | |
| Modificada | Alta (8.2) | 0.46% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the handling of network… | |
| Modificada | Alta (8.8) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the prl_hypervisor module. The… | |
| Modificada | Alta (8.2) | 0.48% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the prl_naptd process. The… | |
| Modificada | Media (6) | 0.55% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the OEMNet… | |
| Modificada | Media (6.5) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the prl_hypervisor kext.… | |
| Modificada | Alta (8.8) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handler for… | |
| Modificada | Media (6.5) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handler for… | |
| Modificada | Alta (8.8) | 0.53% | — | Parallels Desktop | 25/8/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the hypervisor kernel… | |
| Modificada | Crítica (9.9) | 4.0% | — | Parallels Remote Application Server | 24/7/2020 | 17/6/2026 | Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it… | |
| Modificada | Media (5.5) | 0.51% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the IOCTL handler. The… | |
| Modificada | Alta (8.8) | 0.55% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the IOCTL handler. The… | |
| Modificada | Media (6.7) | 0.42% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component.… | |
| Modificada | Media (6.7) | 0.37% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component.… | |
| Modificada | Media (4.4) | 0.53% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.1-47117. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI… | |
| Modificada | Media (6.7) | 0.61% | — | Parallels Desktop | 23/3/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.0-47107 . An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the VGA virtual… | |
| Modificada | Alta (7.5) | 1.7% | — | Cpan Parallel\ | 31/1/2020 | 16/6/2026 | Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files. | |
| Modificada | Alta (7.5) | 1.1% | — | Parallels | 21/1/2020 | 17/6/2026 | Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.parallels.com web site. | |
| Modificada | Alta (7.8) | 0.50% | — | Parallels Desktop | 7/1/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists… | |
| Modificada | Media (6.1) | 0.79% | — | Parallels Plesk Panel | 13/11/2019 | 17/6/2026 | Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter. | |
| Modificada | Alta (7.8) | 0.28% | — | Intel Parallel StudioIntel Parallel Studio XE | 14/12/2018 | 17/6/2026 | Improper directory permissions in the installer for the Intel Parallel Studio before 2019 Gold may allow authenticated users to potentially enable an escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.38% | — | Intel Parallel Studio XE | 14/11/2018 | 17/6/2026 | Heap overflow in Intel Trace Analyzer 2018 in Intel Parallel Studio XE 2018 Update 3 may allow an authenticated user to potentially escalate privileges via local access. | |
| Modificada | Alta (7.8) | 0.38% | — | IBM General Parallel File SystemIBM Spectrum Scale | 13/6/2018 | 17/6/2026 | A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. IBM X-Force ID:… | |
| Modificada | Baja (3.3) | 0.38% | — | IBM Spectrum ScaleIBM General Parallel File System | 2/3/2018 | 17/6/2026 | IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378. | |
| Modificada | Alta (7.5) | 2.0% | — | Parallels Remote Application Server | 28/2/2018 | 17/6/2026 | In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory. A remote, unauthenticated attacker could exploit this weakness to read arbitrary files from the… |