Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
5106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.50% | — | Devolutions Remote Desktop Manager | 26/6/2026 | 29/6/2026 | Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing… | |
| Aplazada | Media (5.3) | 0.31% | — | Jshelpdesk JS Help DeskAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions. | |
| Aplazada | Alta (7.7) | 0.47% | — | Jshelpdesk JS Help DeskAI | 25/6/2026 | 25/6/2026 | Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions. | |
| Aplazada | Media (4.3) | 0.19% | — | MotordeskAI | 24/6/2026 | 25/6/2026 | The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the motordesk_admin_home function. This makes it possible for unauthenticated attackers to update the plugin's configuration settings,… | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | Freedesktop.org LibslirpAI | 24/6/2026 | 25/6/2026 | An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environments (e.g., QEMU) allows a privileged guest VM attacker (root or CAP_NET_RAW) to leak gigabytes of sensitive host-process heap memory via sending… | |
| Pendiente de análisis | Alta (8.7) | 0.11% | 💥 PoC | Anthropic Claude DesktopAI | 24/6/2026 | 25/6/2026 | Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) validates only file presence and a version marker string before booting rootfs.img, but does not verify image content integrity at time-of-use. A local attacker with… | |
| Analizada | Crítica (9.6) | 0.70% | — | Autodesk Fusion | 22/6/2026 | 24/6/2026 | A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user. | |
| Aplazada | Alta (8.8) | 0.56% | — | Line Desktop MCPAI | 19/6/2026 | 23/6/2026 | Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. `line-desktop-mcp` supports a `--http-mode` Streamable HTTP transport for use with clients such as n8n. In this mode the server binds to… | |
| Aplazada | Alta (8.5) | 0.17% | — | Realtimes Desktop ServiceAI | 19/6/2026 | 29/9/2026 | RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories to execute arbitrary code with LocalSystem privileges during service startup or system… | |
| Analizada | Alta (8.5) | 0.20% | — | Anydesk | 19/6/2026 | 6/10/2026 | AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system… | |
| Analizada | Media (5.5) | 0.12% | — | Autodesk Revit | 17/6/2026 | 29/6/2026 | A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition. | |
| Aplazada | Crítica (9.4) | 0.57% | — | Openhuman Desktop AgentAI | 17/6/2026 | 10/8/2026 | The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. | |
| Analizada | Media (5.5) | 0.15% | — | Devolutions Remote Desktop Manager | 16/6/2026 | 17/6/2026 | Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain. | |
| Modificada | Alta (8.8) | 0.44% | — | Devolutions Remote Desktop Manager | 16/6/2026 | 20/7/2026 | Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action. This… | |
| Aplazada | Crítica (9.8) | 0.56% | 💥 PoC | WP ZendeskAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. | |
| Aplazada | Alta (7.4) | 0.28% | — | Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI | 15/6/2026 | 17/6/2026 | Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Elex Wordpress Helpdesk & Customer Ticketing SystemAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Jshelpdesk JS Help DeskAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Jshelpdesk JS Help DeskAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Wpdesk Woocommerce PDF Invoices Packing SlipsAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions. | |
| Analizada | Media (6.5) | 0.36% | — | Mattermost Desktop | 15/6/2026 | 17/6/2026 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost Advisory ID: MMSA-2026-00652 | |
| Analizada | Alta (7.7) | 0.32% | — | Mattermost Desktop | 15/6/2026 | 17/6/2026 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external… | |
| Analizada | Media (5.4) | 0.23% | — | Langflow Desktop | 11/6/2026 | 17/6/2026 | IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Aplazada | Alta (8.4) | 0.41% | 💥 PoC | Mate-desktop AtrilAI | 10/6/2026 | 28/7/2026 | Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF… | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |