Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
–

5108 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.36%—Fabulatech USB FOR Remote Desktop24/5/202317/6/2026
A vulnerability was found in FabulaTech USB for Remote Desktop 6.1.0.0. It has been rated as problematic. Affected by this issue is the function 0x220448/0x220420/0x22040c/0x220408 of the component IoControlCode Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The…
ModificadaCrítica (9.8)0.88%—Oretnom23 Student Study Center Desk Management System18/5/202317/6/2026
Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability.
ModificadaMedia (5.4)0.46%—Help Desk WP Project Help Desk WP15/5/202317/6/2026
The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.
ModificadaAlta (7.8)0.23%—Autodesk 3DS MAX USD12/5/202317/6/2026
A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds write vulnerability which could result in code execution.
ModificadaAlta (7.8)0.23%—Autodesk 3DS MAX USD12/5/202317/6/2026
A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result in code execution.
ModificadaAlta (7.8)0.23%—Autodesk 3DS MAX USD12/5/202317/6/2026
A malicious actor may convince a user to open a malicious USD file that may trigger an uninitialized pointer which could result in code execution.
ModificadaAlta (7.8)0.24%—Autodesk 3DS MAX USD12/5/202317/6/2026
A malicious actor may convince a user to open a malicious USD file that may trigger a use-after-free vulnerability which could result in code execution.
ModificadaAlta (7.8)0.22%—Autodesk Infraworks12/5/202317/6/2026
A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability.
AnalizadaMedia (5.3)1.2%—Microsoft Remote Desktop APP9/5/202317/6/2026
Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability
ModificadaCrítica (9.8)22%💥 ExploitAppium-desktop2/5/202317/6/2026
OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.
ModificadaMedia (5.4)0.36%—Mattermost Desktop2/5/202317/6/2026
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
ModificadaMedia (6.5)0.56%—Wpruby Ruby Help Desk2/5/202317/6/2026
The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.
ModificadaMedia (5.5)0.18%—HP Elite Dragonfly G3 FirmwareHP Dragonfly Folio G3 FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX Firmware+8728/4/202317/6/2026
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability.
ModificadaMedia (6.3)0.29%—Docker Desktop27/4/202317/6/2026
Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerStartRequest class. This allows exploiting a symlink vulnerability in…
ModificadaAlta (7.8)0.30%—Docker Desktop27/4/202317/6/2026
Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation.
ModificadaAlta (7.1)0.34%—Docker Desktop27/4/202317/6/2026
Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder parameter for DockerDesktop.vhdx, a similar issue to CVE-2022-31647.
ModificadaAlta (7.1)0.33%—Docker Desktop27/4/202317/6/2026
Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659.
ModificadaMedia (4.9)3.0%—Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus26/4/202317/6/2026
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
ModificadaMedia (6.5)0.42%—Devolutions Remote Desktop Manager25/4/202317/6/2026
Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector.
ModificadaMedia (6.1)0.19%—Pingidentity Desktop25/4/202317/6/2026
PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted before the time-based lockout is activated.
ModificadaMedia (5.5)0.08%—UI Desktop19/4/202317/6/2026
Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with access to UI Desktop configuration files to decrypt their content.This vulnerability is fixed in Version 0.62.3 and later.
ModificadaMedia (5.5)0.16%—UI Desktop19/4/202317/6/2026
A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VPN credentials while UID VPN is starting.This vulnerability is fixed in Version 0.62.3 and later.
ModificadaAlta (7.8)0.16%—UI Desktop19/4/202317/6/2026
A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a malicious actor with local access to a Windows device running said application to submit arbitrary commands as SYSTEM.This vulnerability is fixed in Version 0.62.3 and later.
ModificadaCrítica (9.8)1.2%—Oretnom23 Student Study Center Desk Management System18/4/202317/6/2026
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack can be launched remotely. The exploit…
ModificadaCrítica (9.8)0.77%—Oretnom23 Student Study Center Desk Management System18/4/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been…