Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
117 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.50% | 💥 PoC | Fabulatech USB FOR Remote Desktop | 17/6/2020 | 17/6/2026 | ftusbbus2.sys in FabulaTech USB for Remote Desktop through 2020-02-19 allows privilege escalation via crafted IoCtl code related to a USB HID device. | |
| Modificada | Media (5.5) | 4.7% | — | Microsoft Remote Desktop Connection Manager | 12/3/2020 | 17/6/2026 | An information disclosure vulnerability exists in the Remote Desktop Connection Manager (RDCMan) application when it improperly parses XML input containing a reference to an external entity, aka 'Remote Desktop Connection Manager Information Disclosure Vulnerability'. | |
| Modificada | Alta (8) | 71% | 💥 PoC | Microsoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows 11 21h2Microsoft Windows 7+6 | 15/7/2019 | 17/6/2026 | A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. | |
| Modificada | Alta (7.5) | 2.0% | — | Cybelesoft Thinfinity Remote Desktop Workstation | 6/10/2017 | 17/6/2026 | Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit allows remote attackers to download arbitrary files via a .. (dot dot) in an unspecified parameter. | |
| Modificada | Baja (3.7) | 0.34% | — | Apple MAC OS XApple Remote Desktop | 14/11/2015 | 16/6/2026 | The Remote Desktop full-screen feature in Apple OS X before 10.9 and Apple Remote Desktop before 3.7 sends dialog-box text to a connected remote host upon being woken from sleep, which allows physically proximate attackers to bypass intended access restrictions by entering a command in this box. | |
| Modificada | Media (5.4) | 0.27% | — | Islonline ISL Light Remote Desktop | 9/9/2014 | 17/6/2026 | The ISL Light Remote Desktop (aka com.islonline.isllight.mobile.android) application 2.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Deskroll Remote Desktop | 9/9/2014 | 17/6/2026 | The DeskRoll Remote Desktop (aka com.deskroll.client1) application 0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.1% | — | Apple Remote Desktop | 24/10/2013 | 16/6/2026 | Apple Remote Desktop before 3.7 does not properly use server authentication-type information during decisions about whether to present an unencrypted-connection warning message, which allows remote attackers to obtain sensitive information in opportunistic circumstances by sniffing the network during an unintended… | |
| Modificada | Alta (7.5) | 11% | — | Apple Remote DesktopApple MAC OS X | 24/10/2013 | 16/6/2026 | Format string vulnerability in Screen Sharing Server in Apple Mac OS X before 10.9 and Apple Remote Desktop before 3.5.4 allows remote attackers to execute arbitrary code via format string specifiers in a VNC username. | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Remote Desktop Connection | 9/4/2013 | 16/6/2026 | The Remote Desktop ActiveX control in mstscax.dll in Microsoft Remote Desktop Connection Client 6.1 and 7.0 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a web page that triggers access to a deleted object, and allows remote RDP servers to execute arbitrary… | |
| Modificada | Media (4.3) | 1.7% | — | Apple Remote Desktop | 22/8/2012 | 16/6/2026 | Apple Remote Desktop before 3.6.1 does not recognize the "Encrypt all network data" setting during connections to third-party VNC servers, which allows remote attackers to obtain cleartext VNC session content by sniffing the network. | |
| Modificada | Alta (7.4) | 7.2% | — | Microsoft Remote Desktop Connection ClientMicrosoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows XP+3 | 9/3/2011 | 16/6/2026 | Untrusted search path vulnerability in the client in Microsoft Remote Desktop Connection 5.2, 6.0, 6.1, and 7.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp file, aka "Remote Desktop Insecure Library Loading… | |
| Modificada | Alta (7.2) | 0.33% | — | Apple Remote Desktop | 18/11/2006 | 16/6/2026 | Apple Remote Desktop before 3.1 uses insecure permissions for certain built-in packages, which allows local users on an Apple Remote Desktop administration system to modify the packages and gain root privileges on client systems that use the packages. | |
| Modificada | Alta (7.2) | 0.42% | — | Apple Remote DesktopApple MAC OS X | 19/9/2006 | 16/6/2026 | Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation. NOTE: it could be argued that the issue is not in Remote… | |
| Modificada | Alta (7.4) | 16% | 💥 PoC | Microsoft Remote Desktop ConnectionMicrosoft Windows Terminal Services Using RDP | 1/6/2005 | 16/6/2026 | Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks. | |
| Modificada | Alta (10) | 3.4% | — | Apple Remote Desktop | 9/2/2005 | 16/6/2026 | Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which allows remote authenticated users to execute arbitrary code when loginwindow is active via Fast User Switching. | |
| Modificada | Media (5) | 2.6% | — | Mcafee Remote Desktop 32 | 22/8/2001 | 16/6/2026 | McAfee Remote Desktop 3.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of packets to port 5045. |