Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.4)0.87%—Oracle Hyperion Workspace23/7/201917/6/2026
Vulnerability in the Oracle Hyperion Workspace component of Oracle Hyperion (subcomponent: UI and Visualization). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Workspace. Successful attacks…
AnalizadaCrítica (9.8)8.1%⚠ Explotación activaCitrix ReceiverCitrix Workspace22/5/201912/8/2026
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
ModificadaAlta (7.8)1.0%—Ivanti Workspace Control5/4/201917/6/2026
An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed session can bypass Workspace Control security features configured for this session by resetting the session context.
ModificadaAlta (7.8)1.0%—Ivanti Workspace Control15/10/201817/6/2026
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can decrypt the encrypted datastore or relay server password by leveraging an unspecified attack vector.
ModificadaAlta (7.8)0.59%—Ivanti Workspace Control15/10/201817/6/2026
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can execute processes with elevated privileges via an unspecified attack vector.
ModificadaAlta (7.8)1.3%—Ivanti Workspace Control15/10/201817/6/2026
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute arbitrary code by leveraging multiple unspecified attack vectors.
ModificadaMedia (5.5)0.99%—Ivanti Workspace Control15/10/201817/6/2026
An issue was discovered in Ivanti Workspace Control before 10.3.0.0 and RES One Workspace, when file and folder security are configured. A local authenticated user can bypass file and folder security restriction by leveraging an unspecified attack vector.
ModificadaMedia (5.3)1.2%—Vmware Workspace ONE11/9/201817/6/2026
The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vulnerability relates to unencrypted filenames and associated metadata in SQLite database for the Content Locker.
ModificadaAlta (7.8)0.58%—Sophos Invincea Dell Protected Workspace24/4/201817/6/2026
Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver communication channel and additional insufficient checks allow any application to turn off some of the protection mechanisms provided by the Invincea product.
ModificadaMedia (6.8)0.78%💥 PoCKDE Plasma-workspaceDebian Linux7/2/201817/6/2026
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution.…
ModificadaMedia (5.3)2.1%—KDE Plasma-workspace7/2/201817/6/2026
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.
ModificadaAlta (7.5)1.4%—Blackberry Workspaces VappBlackberry Workspaces Appliance-x16/10/201717/6/2026
An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side applications by crafting a request for specific files.
ModificadaCrítica (9.8)1.6%—Blackberry Workspaces VappBlackberry Workspaces Appliance-x16/10/201717/6/2026
A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST request.
ModificadaAlta (8.8)0.86%—Blackberry Workspaces9/8/201717/6/2026
An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's workspace by making multiple login requests to the server.
ModificadaMedia (6.1)0.95%—Blackberry Appliance-xBlackberry Workspaces Vapp13/1/201717/6/2026
A reflected cross-site scripting vulnerability in the BlackBerry WatchDox Server components Appliance-X, version 1.8.1 and earlier, and vAPP, versions 4.6.0 to 5.4.1, allows remote attackers to execute script commands in the context of the affected browser by persuading a user to click an attacker-supplied malicious…
ModificadaMedia (6.8)0.44%—KDE KscreenlockerKDE Plasma-workspaceFedoraproject FedoraOpensuse Leap23/12/201617/6/2026
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
ModificadaMedia (5.7)1.0%—Symantec Workspace StreamingSymantec Workspace Virtualization12/7/201617/6/2026
The management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read arbitrary files by modifying the file-download configuration file.
ModificadaMedia (5.7)1.8%—Symantec Workspace StreamingSymantec Workspace Virtualization12/7/201617/6/2026
Directory traversal vulnerability in the file-download configuration file in the management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to…
ModificadaMedia (6.9)0.45%—Symantec Workspace Streaming22/4/201517/6/2026
Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by…
ModificadaMedia (4.3)1.4%—KDE Plasma-workspaceKde-workspace26/1/201517/6/2026
kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.
ModificadaMedia (4.3)1.2%—KDE Plasma-workspace26/1/201517/6/2026
plasma-workspace before 5.1.95 allows remote attackers to obtain passwords via a Trojan horse Look and Feel package.
ModificadaAlta (7.2)0.39%—KDE Plasma-desktopKde-workspace6/12/201417/6/2026
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.
ModificadaAlta (7.9)42%💥 ExploitSymantec Workspace Streaming16/5/201417/6/2026
The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLRPC request over HTTPS.
ModificadaMedia (5)2.4%—Kde-workspaceKDE SCOpensuse16/9/201316/6/2026
KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via (1) an invalid salt or a (2) DES or (3) MD5 encrypted password, when FIPS-140 is enable, to…
ModificadaMedia (6.6)1.0%💥 ExploitSymantec Workspace Virtualization5/8/201316/6/2026
Symantec Workspace Virtualization before 6.x before 6.4.1953.0, when a virtual application layer is configured, allows local users to gain privileges via an application that performs crafted interaction with the operating system.
Orbitaley — Vulnerabilidades