Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.72% | — | Ivanti Workspace Control | 1/9/2021 | 17/6/2026 | An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspecified attack vector. As a result, the attacker can start applications with elevated privileges. | |
| Modificada | Alta (7.5) | 0.99% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Vrealize Suite Lifecycle Manager | 31/8/2021 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity… | |
| Modificada | Crítica (9.8) | 1.2% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Vrealize Suite Lifecycle Manager | 31/8/2021 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious… | |
| Modificada | Alta (7.5) | 0.96% | — | Vmware Workspace ONE UEM Console | 31/8/2021 | 17/6/2026 | VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due to improper rate limiting. | |
| Modificada | Media (5.3) | 0.79% | — | Siemens Teamcenter Active Workspace | 13/7/2021 | 17/6/2026 | A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versions < V5.0.7), Teamcenter Active Workspace V5.1 (All versions < V5.1.4). The affected application allows verbose error messages which allow leaking of sensitive information, such as… | |
| Modificada | Media (6.1) | 0.58% | — | Siemens Teamcenter Active Workspace | 13/7/2021 | 17/6/2026 | A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versions < V5.0.7), Teamcenter Active Workspace V5.1 (All versions < V5.1.4). A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the affected devices… | |
| Modificada | Media (4.3) | 0.90% | — | Siemens Teamcenter Active Workspace | 13/7/2021 | 17/6/2026 | A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versions < V5.0.7), Teamcenter Active Workspace V5.1 (All versions < V5.1.4). By sending malformed requests, a remote attacker could leak an application token due to an error not… | |
| Modificada | Alta (7.8) | 0.24% | — | Citrix Workspace | 27/5/2021 | 17/6/2026 | An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4. | |
| Modificada | Alta (8.8) | 0.96% | — | Blackberry Workspaces Server | 13/5/2021 | 17/6/2026 | An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) version(s) 10.1, 9.1 and earlier could allow an attacker to potentially gain access to the application in the context of the targeted user’s account. | |
| Modificada | Media (6.1) | 0.80% | — | Vmware Workspace ONE Unified Endpoint Management | 11/5/2021 | 17/6/2026 | VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 20.8.0.28, 2007 prior to 20.7.0.14,2006 prior to 20.6.0.19, 2005 prior to 20.5.0.46, 2004 prior to 20.4.0.21, 2003 prior to 20.3.0.23, 2001 prior to 20.1.0.32, 1912 prior… | |
| Modificada | Alta (8.8) | 0.33% | — | Tibco Iprocess Workspace Browser | 10/11/2020 | 17/6/2026 | The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Site Request Forgery (CSRF) attack on the affected system. A successful attack using this vulnerability requires human… | |
| Modificada | Media (6.5) | 1.7% | — | Jenkins Copy Data TO Workspace | 16/9/2020 | 17/6/2026 | Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller. | |
| Modificada | Alta (8.8) | 2.1% | — | Citrix Workspace | 24/7/2020 | 17/6/2026 | Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running. | |
| Modificada | Alta (7.8) | 0.58% | 💥 PoC | Citrix Workspace APP | 8/6/2020 | 17/6/2026 | Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application. | |
| Modificada | Alta (7.8) | 0.57% | 💥 PoC | Citrix Workspace APP | 8/6/2020 | 17/6/2026 | Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application. | |
| Modificada | Alta (7.8) | 0.47% | — | Ivanti Workspace Control | 18/5/2020 | 17/6/2026 | In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights. | |
| Analizada | Media (6.5) | 86% | ⚠ Explotación activa💥 Exploit | Saltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+2 | 30/4/2020 | 17/6/2026 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users. | |
| Modificada | Media (5.4) | 0.55% | — | Matrix42 Workspace Management | 15/4/2020 | 17/6/2026 | The Search parameter of the Software Catalogue section of Matrix42 Workspace Management 9.1.2.2765 and below accepts unfiltered parameters that lead to multiple reflected XSS issues. | |
| Modificada | Media (5.4) | 0.77% | — | Matrix42 Workspace Management | 15/4/2020 | 17/6/2026 | Matrix42 Workspace Management 9.1.2.2765 and below allows stored XSS via unfiltered description parameters, as demonstrated by the comment field of a special order for individual software. | |
| Modificada | Media (5.5) | 0.48% | — | Ivanti Workspace Control | 4/4/2020 | 17/6/2026 | Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material). | |
| Modificada | Crítica (9.8) | 2.9% | — | Ivanti Workspace Control | 19/3/2020 | 17/6/2026 | An issue was discovered in Ivanti Workspace Control 10.3.110.0. One is able to bypass Ivanti's FileGuard folder protection by renaming the WMTemp work folder used by PowerGrid. A malicious PowerGrid XML file can then be created, after which the folder is renamed back to its original value. Also, CVE-2018-15591… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Apache GeodeApache TomcatFedoraproject FedoraOracle Agile Engineering Data Management+17 | 24/2/2020 | 25/8/2026 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising.… | |
| Modificada | Media (5.9) | 0.80% | — | Vmware Workspace ONE BoxerVmware Workspace ONE ContentVmware Workspace ONE Intelligent HUBVmware Workspace ONE Notebook+5 | 17/1/2020 | 17/6/2026 | VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability. | |
| Modificada | Alta (7.8) | 0.47% | — | Ivanti Workspace Control | 17/12/2019 | 17/6/2026 | In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Preferences, when it is enabled. As a result, the attacker can start applications that should be blocked. | |
| Modificada | Alta (7.5) | 2.8% | — | Kde-workspaceDebian Linux | 10/12/2019 | 16/6/2026 | kde-workspace before 4.10.5 has a memory leak in plasma desktop |