Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
5108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.39% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a malicious server could get the desktop client to encrypt files with a key known to… | |
| Modificada | Media (6.4) | 0.68% | — | Nextcloud DesktopNextcloud | 4/4/2023 | 17/6/2026 | Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder… | |
| Modificada | Media (6.1) | 0.68% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder structure, and add new files. Users should… | |
| Modificada | Media (6.5) | 1.1% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can recover and modify the contents of end-to-end encrypted files. Users should upgrade the Nextcloud Desktop client to 3.6.5 to receive a patch.… | |
| Modificada | Media (6.5) | 0.48% | — | Devolutions Remote Desktop Manager | 2/4/2023 | 17/6/2026 | Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive information via the error message dialog that displays the password in clear text. | |
| Modificada | Media (6.5) | 0.44% | — | Devolutions Remote Desktop Manager | 2/4/2023 | 17/6/2026 | Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision. | |
| Modificada | Media (5.4) | 1.0% | 💥 PoC | Trudesk Project Trudesk | 29/3/2023 | 17/6/2026 | Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function. | |
| Modificada | Alta (7.5) | 0.52% | — | Zoom RoomsZoomZoom Virtual Desktop Infrastructure | 27/3/2023 | 17/6/2026 | Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond… | |
| Modificada | Alta (7.8) | 0.90% | — | X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+14 | 27/3/2023 | 17/6/2026 | A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote… | |
| Modificada | Alta (8.8) | 0.80% | — | Ladybirdweb Faveo Helpdesk | 24/3/2023 | 17/6/2026 | Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection. | |
| Modificada | Media (6.5) | 1.1% | — | Ladybirdweb Faveo Servicedesk | 24/3/2023 | 17/6/2026 | Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack. | |
| Modificada | Media (5.4) | 0.65% | — | Oretnom23 Student Study Center Desk Management System | 22/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file /admin/reports/index.php of the component GET Parameter Handler. The manipulation of the argument date_to leads to cross site scripting. It is possible… | |
| Modificada | Media (6.1) | 0.59% | — | Oretnom23 Student Study Center Desk Management System | 22/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/assign/assign.php. The manipulation of the argument sid leads to cross site scripting. The attack may be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 0.78% | — | Oretnom23 Student Study Center Desk Management System | 22/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/assign/assign.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely.… | |
| Modificada | Crítica (9.8) | 0.54% | — | Oretnom23 Student Study Center Desk Management System | 17/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=reports&date_from=2023-02-17&date_to=2023-03-17 of the component Report Handler. The manipulation of the argument… | |
| Modificada | Crítica (9.8) | 1.1% | — | Oretnom23 Student Study Center Desk Management System | 17/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file Master.php?f=delete_img of the component POST Parameter Handler. The manipulation of the argument path with the input C%3A%2Ffoo.txt leads to path… | |
| Modificada | Crítica (9.8) | 0.54% | — | Oretnom23 Student Study Center Desk Management System | 17/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as critical. This issue affects the function view_student of the file admin/?page=students/view_student. The manipulation of the argument id with the input 3' AND (SELECT 2100 FROM (SELECT(SLEEP(5)))FWlC) AND… | |
| Modificada | Alta (7.5) | 0.98% | — | Zoom RoomsZoom Virtual Desktop InfrastructureZoom | 16/3/2023 | 17/6/2026 | Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, transmitted text to Microsoft’s… | |
| Modificada | Alta (7.2) | 0.71% | — | Oretnom23 Student Study Center Desk Management System | 15/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The… | |
| Modificada | Alta (7.1) | 0.22% | — | Docker Desktop | 13/3/2023 | 17/6/2026 | Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to docker.raw.sock, or npipe:////.pipe/docker_engine_linux on Windows, via the -H (--host) CLI flag or the DOCKER_HOST environment variable and launch containers without the… | |
| Modificada | Alta (7.8) | 0.27% | — | Docker Desktop | 13/3/2023 | 17/6/2026 | Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL. | |
| Modificada | Media (6.5) | 1.1% | — | Devolutions Remote Desktop Manager | 10/3/2023 | 17/6/2026 | Improper removal of sensitive data in the entry edit feature of Hub Business submodule in Devolutions Remote Desktop Manager PowerShell Module 2022.3.1.5 and earlier allows an authenticated user to access sensitive data on entries that were edited using the affected submodule. | |
| Modificada | Crítica (9.8) | 2.2% | — | Wyomind Help Desk | 8/3/2023 | 17/6/2026 | Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting. | |
| Modificada | Crítica (9.8) | 1.4% | — | Wyomind Help Desk | 8/3/2023 | 17/6/2026 | An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field. | |
| Modificada | Crítica (9) | 1.0% | — | Wyomind Help Desk | 8/3/2023 | 17/6/2026 | Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field. |