Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
5106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.26% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. | |
| Analizada | Alta (7.8) | 0.28% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Aplazada | Alta (7.3) | 0.16% | — | Arksigner Software AND Hardware Industry AND Trade INC Arksigner Desktop ClientAI | 28/7/2026 | 28/7/2026 | Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026. | |
| Aplazada | Crítica (9.4) | 0.56% | — | Siyuan DesktopAI | 27/7/2026 | 17/9/2026 | SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access… | |
| Aplazada | Alta (8.7) | 1.1% | — | Nitroshare DesktopAI | 27/7/2026 | 28/7/2026 | NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit… | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | Systemd-homedAIFreedesktop AccountsserviceAI | 24/7/2026 | 24/7/2026 | A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process. | |
| Aplazada | Crítica (9.8) | 0.95% | — | Customer Support Ticket System HelpdeskAI | 23/7/2026 | 23/7/2026 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes it possible for unauthenticated… | |
| Analizada | Alta (7.5) | 0.66% | — | Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center | 17/7/2026 | 22/7/2026 | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 0.42% | — | Mattermost Desktop | 17/7/2026 | 30/7/2026 | Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a malformed one. Mattermost Advisory ID: MMSA-2026-00678 | |
| Analizada | Media (6.5) | 0.42% | — | Mattermost Desktop | 17/7/2026 | 30/7/2026 | Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded image that misses one of those headers. Mattermost Advisory ID:… | |
| Analizada | Crítica (9.8) | 0.53% | — | Zoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 16/7/2026 | 11/8/2026 | Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access. | |
| Analizada | Alta (7) | 0.14% | — | Zoom Workplace Virtual Desktop Infrastructure | 16/7/2026 | 12/8/2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. | |
| Analizada | Alta (7) | 0.10% | — | Remote Control FOR Zoom Contact CenterZoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 16/7/2026 | 17/8/2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. | |
| Analizada | Alta (7.8) | 0.17% | — | Adobe Creative Cloud Desktop Application | 14/7/2026 | 28/8/2026 | Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is… | |
| Analizada | Alta (7.8) | 0.23% | — | Adobe Creative Cloud Desktop Application | 14/7/2026 | 28/8/2026 | Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Media (5.5) | 0.14% | — | Anydesk | 13/7/2026 | 14/7/2026 | AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Media (5.5) | 0.14% | — | Anydesk | 13/7/2026 | 14/7/2026 | AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Aplazada | Media (6.5) | 0.22% | — | Wpdesk Flexible Refund AND Return Order FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Refund and Return Order for WooCommerce flexible-refund-and-return-order-for-woocommerce allows Stored XSS.This issue affects Flexible Refund and Return Order for WooCommerce: from n/a through <=… | |
| Aplazada | Media (4.3) | 0.35% | — | ThrivedeskAI | 11/7/2026 | 13/7/2026 | The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cache deletion due to a missing capability check on the 'thrivedesk_clear_cache' AJAX action in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.39% | — | Wpdesk PDF Invoices Packing Slips FOR WoocommerceAI | 11/7/2026 | 13/7/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.7) | 0.50% | 💥 PoC | RustdeskAI | 10/7/2026 | 11/8/2026 | RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for a full Remote session. An authenticated remote peer can exploit this… | |
| Pendiente de análisis | Alta (8.8) | 0.18% | — | OpenjdkAIUbuntuAIMailcapAIFreedesktop Xdg-desktop-portal-gtkAI | 8/7/2026 | 14/7/2026 | A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | 💥 PoC | HP DeskjetAI | 6/7/2026 | 31/8/2026 | Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs. | |
| Aplazada | Media (5.5) | 0.54% | — | Tiddly Gittly Tidgi DesktopAI | 5/7/2026 | 6/7/2026 | A vulnerability was found in tiddly-gittly TidGi-Desktop up to 0.13.0. This impacts an unknown function of the file src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts of the component Git Repository Import. The manipulation results in code injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Alta (7.2) | 0.33% | — | RustdeskAI | 28/6/2026 | 18/7/2026 | RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and… |