Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
–

5107 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.2%—Freedesktop Poppler11/8/202317/6/2026
An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.
ModificadaAlta (7.8)0.14%—Topconpositioning Mavinci Desktop11/8/202317/6/2026
Incorrect default permissions in the MAVinci Desktop Software for Intel(R) Falcon 8+ before version 6.2 may allow authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.32%—Ivanti Desktop & Server Management10/8/202317/6/2026
DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.
ModificadaCrítica (9.8)1.4%—Zoom Virtual Desktop InfrastructureZoom8/8/202317/6/2026
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.
ModificadaMedia (4.9)1.1%—Zoom RoomsZoom Virtual Desktop InfrastructureZoom8/8/202317/6/2026
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.
ModificadaMedia (6.5)1.2%—Zoom RoomsZoom Virtual Desktop InfrastructureZoom8/8/202317/6/2026
La aplicación del lado del cliente de la seguridad del lado del servidor en los clientes en Zoom anteriores a la versión 5.14.10 puede permitir que un usuario autenticado permita la divulgación de información a través del acceso a la red.
ModificadaAlta (7.5)1.5%—Zoom RoomsZoom Virtual Desktop InfrastructureZoom8/8/202317/6/2026
El desbordamiento del búfer en los clientes Zoom anteriores a la versión 5.14.5 puede permitir a un usuario no autenticado activar una denegación de servicio a través del acceso a la red.
ModificadaAlta (7.8)1.2%💥 ExploitWebkul Uvdesk1/8/202317/6/2026
Una vulnerabilidad de carga de archivos arbitrarios en Uvdesk 1.1.3 permite a los atacantes ejecutar código arbitrario mediante la carga de un archivo de imagen manipulado.
ModificadaMedia (5.5)0.90%—Freedesktop Poppler31/7/202317/6/2026
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
ModificadaMedia (6.1)0.36%—Truedesk26/7/202317/6/2026
* A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a user chat box.
ModificadaMedia (6.1)0.44%—Truedesk26/7/202317/6/2026
Una vulnerabilidad de Cross-Site Scripting (XSS) en Truedesk v1.2.2 permite a los atacantes ejecutar secuencias de comandos web o HTML arbitrarias a través de un payload manipulado inyectado en el parámetro del nombre del equipo.
ModificadaAlta (7.2)0.96%—Deskpro21/7/20239/7/2026
Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted URL.
ModificadaMedia (6.5)0.35%—Oracle WEB Applications Desktop Integrator18/7/202317/6/2026
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: MS Excel Specific). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications…
ModificadaMedia (4.3)0.30%—Citrix Virtual Apps AND DesktopsCitrix Linux Virtual Delivery Agent10/7/202317/6/2026
Users with only access to launch VDA applications can launch an unauthorized desktop
ModificadaCrítica (9.8)0.63%—Anakeen Dynacase Webdesk10/7/202317/6/2026
A vulnerability was found in Dynacase Webdesk and classified as critical. Affected by this issue is the function freedomrss_search of the file freedomrss_search.php. The manipulation leads to sql injection. Upgrading to version 3.2-20180305 is able to address this issue. The patch is identified as…
ModificadaMedia (5.4)3.5%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus7/7/202317/6/2026
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
ModificadaAlta (7.5)1.1%—Anydesk3/7/202317/6/2026
AnyDesk 7.0.8 allows remote Denial of Service.
ModificadaAlta (7)0.13%—HP 260 G4 Desktop Mini FirmwareHP T430 FirmwareHP T628 FirmwareHP 240 G10 Firmware+5530/6/202317/6/2026
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.
ModificadaAlta (7.8)0.35%—Autodesk 3DS MAXAutodesk NavisworksAutodesk RevitAutodesk Vred27/6/202317/6/2026
A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
ModificadaAlta (7.8)0.26%—Autodesk Navisworks27/6/202317/6/2026
A maliciously crafted SKP file in Autodesk Navisworks 2023 and 2022 be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
ModificadaAlta (7.8)0.24%—Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+1327/6/202317/6/2026
A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.8)0.24%—Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+1327/6/202317/6/2026
A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution.
ModificadaMedia (5.4)0.47%—Ladybirdweb Faveo Helpdesk24/6/202317/6/2026
Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the application. This occurs because the application is vulnerable to stored XSS.
ModificadaAlta (7.8)0.22%—Autodesk Installer23/6/202317/6/2026
A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead to a Privilege Escalation vulnerability.
ModificadaAlta (7.8)0.25%—Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+1323/6/202317/6/2026
A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution.