Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
5108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Nanoleaf Desktop | 18/4/2023 | 9/7/2026 | Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request. | |
| Modificada | Alta (7.8) | 0.64% | — | Autodesk FBX Software Development KIT | 17/4/2023 | 17/6/2026 | A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution. | |
| Modificada | Alta (7.8) | 0.53% | — | Autodesk FBX Software Development KIT | 17/4/2023 | 17/6/2026 | A user may be tricked into opening a malicious FBX file that may exploit a stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution. | |
| Modificada | Alta (7.8) | 0.49% | — | Autodesk FBX Software Development KIT | 17/4/2023 | 17/6/2026 | An Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK version 2020 or prior may lead to code execution through maliciously crafted FBX files or information disclosure. | |
| Modificada | Alta (7.8) | 0.30% | — | Autodesk Maya USD | 17/4/2023 | 17/6/2026 | A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds write vulnerability which may result in code execution. | |
| Modificada | Alta (7.8) | 0.30% | — | Autodesk Maya USD | 17/4/2023 | 17/6/2026 | A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds read vulnerability which may result in code execution. | |
| Modificada | Alta (7.8) | 0.30% | — | Autodesk Maya USD | 17/4/2023 | 17/6/2026 | A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which may result in code execution. | |
| Modificada | Media (6.1) | 0.45% | — | Freshworks Freshdesk | 17/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Freshdesk Plugin 1.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to open redirect. The attack may be launched remotely. Upgrading to version 1.8 is able to address this issue. The patch is identified as… | |
| Modificada | Alta (7.8) | 0.30% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 14/4/2023 | 17/6/2026 | A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 14/4/2023 | 17/6/2026 | A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 14/4/2023 | 17/6/2026 | A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to write beyond the allocated buffer causing a Stack Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 14/4/2023 | 17/6/2026 | A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to cause an Integer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 14/4/2023 | 17/6/2026 | A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process. | |
| Modificada | Media (6.5) | 0.71% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation… | |
| Modificada | Alta (8.8) | 0.96% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdeskintegration/saml/user/createorupdate endpoint, the /settings/guest-settings endpoint, the /settings/samlusers-settings endpoint, and the /settings/users-settings endpoint. A malicious user (already… | |
| Modificada | Media (6.5) | 0.72% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/{N]/{C]/websocket endpoint. A malicious unauthenticated user can access cached files in the OnlyOffice backend of other users by guessing the file ID of a target file. | |
| Modificada | Crítica (9.8) | 1.0% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is not checked properly, and can be bypassed by passing any string… | |
| Modificada | Crítica (9.8) | 1.0% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding… | |
| Modificada | Media (6.5) | 0.44% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user. | |
| Analizada | Media (6.5) | 2.1% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+10 | 11/4/2023 | 17/6/2026 | Remote Desktop Protocol Client Information Disclosure Vulnerability | |
| Modificada | Media (6.5) | 0.52% | — | Devolutions Remote Desktop Manager | 11/4/2023 | 17/6/2026 | Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factor authentication via the application user interface and open entries. | |
| Modificada | Media (4.3) | 0.40% | — | Devolutions Remote Desktop Manager | 11/4/2023 | 17/6/2026 | No access control for the OTP key on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface. | |
| Modificada | Alta (7.5) | 0.55% | — | Docker Desktop | 6/4/2023 | 17/6/2026 | In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information. Only users who have Access Experimental Features enabled and have logged in to a… | |
| Modificada | Media (6.1) | 0.69% | — | Uvdesk Community-skeleton | 4/4/2023 | 17/6/2026 | Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the message sent by the clients in the ticket. | |
| Modificada | Alta (8.8) | 1.6% | — | Uvdesk Community-skeleton | 4/4/2023 | 17/6/2026 | Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers. |