Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

5106 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.50%—Devolutions Remote Desktop Manager26/6/202629/6/2026
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing…
AplazadaMedia (5.3)0.31%—Jshelpdesk JS Help DeskAI26/6/202626/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.
AplazadaAlta (7.7)0.47%—Jshelpdesk JS Help DeskAI25/6/202625/6/2026
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
AplazadaMedia (4.3)0.19%—MotordeskAI24/6/202625/6/2026
The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the motordesk_admin_home function. This makes it possible for unauthenticated attackers to update the plugin's configuration settings,…
Pendiente de análisisMedia (6.5)0.22%—Freedesktop.org LibslirpAI24/6/202625/6/2026
An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environments (e.g., QEMU) allows a privileged guest VM attacker (root or CAP_NET_RAW) to leak gigabytes of sensitive host-process heap memory via sending…
Pendiente de análisisAlta (8.7)0.11%💥 PoCAnthropic Claude DesktopAI24/6/202625/6/2026
Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) validates only file presence and a version marker string before booting rootfs.img, but does not verify image content integrity at time-of-use. A local attacker with…
AnalizadaCrítica (9.6)0.70%—Autodesk Fusion22/6/202624/6/2026
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.
AplazadaAlta (8.8)0.56%—Line Desktop MCPAI19/6/202623/6/2026
Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. `line-desktop-mcp` supports a `--http-mode` Streamable HTTP transport for use with clients such as n8n. In this mode the server binds to…
AplazadaAlta (8.5)0.17%—Realtimes Desktop ServiceAI19/6/202629/9/2026
RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories to execute arbitrary code with LocalSystem privileges during service startup or system…
AnalizadaAlta (8.5)0.20%—Anydesk19/6/20266/10/2026
AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system…
AnalizadaMedia (5.5)0.12%—Autodesk Revit17/6/202629/6/2026
A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.
AplazadaCrítica (9.4)0.57%—Openhuman Desktop AgentAI17/6/202610/8/2026
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.
AnalizadaMedia (5.5)0.15%—Devolutions Remote Desktop Manager16/6/202617/6/2026
Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.
ModificadaAlta (8.8)0.44%—Devolutions Remote Desktop Manager16/6/202620/7/2026
Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action. This…
AplazadaCrítica (9.8)0.56%💥 PoCWP ZendeskAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
AplazadaAlta (7.4)0.28%—Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI15/6/202617/6/2026
Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp; Chat Buttons <= 1.4.8 versions.
AplazadaAlta (8.5)0.36%—Elex Wordpress Helpdesk & Customer Ticketing SystemAI15/6/202617/6/2026
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.
AplazadaMedia (6.5)0.33%—Jshelpdesk JS Help DeskAI15/6/202617/6/2026
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
AplazadaCrítica (9.3)0.40%—Jshelpdesk JS Help DeskAI15/6/202617/6/2026
Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.
AplazadaAlta (7.2)0.54%—Wpdesk Woocommerce PDF Invoices Packing SlipsAI15/6/202617/6/2026
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
AnalizadaMedia (6.5)0.36%—Mattermost Desktop15/6/202617/6/2026
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost Advisory ID: MMSA-2026-00652
AnalizadaAlta (7.7)0.32%—Mattermost Desktop15/6/202617/6/2026
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external…
AnalizadaMedia (5.4)0.23%—Langflow Desktop11/6/202617/6/2026
IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
AplazadaAlta (8.4)0.41%💥 PoCMate-desktop AtrilAI10/6/202628/7/2026
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF…
AnalizadaAlta (7.5)1.0%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+119/6/202623/7/2026
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.