Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
5106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.61% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.5) | 0.61% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (7.5) | 0.47% | — | Microsoft Remote Desktop ClientMicrosoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+3 | 9/6/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (7.5) | 0.47% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Crítica (9.8) | 0.53% | — | Freedesktop Libinput | 4/6/2026 | 22/7/2026 | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution | |
| Aplazada | Baja (2.1) | 0.35% | — | Wonderwhy-er DesktopcommandermcpAI | 3/6/2026 | 22/7/2026 | A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a manipulation of the argument SearchResult[] results in inefficient regular expression complexity. It is possible to… | |
| Aplazada | Baja (2.1) | 0.22% | — | Wonderwhy-er DesktopcommandermcpAI | 3/6/2026 | 22/7/2026 | A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is… | |
| Pendiente de análisis | Alta (8.2) | 0.15% | — | Docker DesktopAI | 2/6/2026 | 22/7/2026 | Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry invalidation event. This issue has been fixed in Docker Desktop 4.76.0. | |
| Analizada | Alta (7.5) | 0.71% | — | Solarwinds WEB Help Desk | 2/6/2026 | 22/7/2026 | SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory. | |
| Pendiente de análisis | Baja (2) | 0.13% | — | Strongdm Desktop ApplicationAIStrongdm Desktop ClientAIMicrosoft WindowsAI | 29/5/2026 | 6/10/2026 | StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS… | |
| Analizada | Alta (7.8) | 0.19% | — | Autodesk 3DS MAX | 26/5/2026 | 24/7/2026 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Media (5.5) | 0.16% | — | Autodesk 3DS MAX | 26/5/2026 | 24/7/2026 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition. | |
| Analizada | Alta (7.8) | 0.19% | — | Autodesk 3DS MAX | 26/5/2026 | 24/7/2026 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.19% | — | Autodesk 3DS MAX | 26/5/2026 | 24/7/2026 | A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Modificada | Media (5.5) | 0.16% | — | Autodesk 3DS MAX | 26/5/2026 | 24/7/2026 | A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition. | |
| Aplazada | Alta (7) | 0.12% | — | Soroush IM Desktop APPAI | 25/5/2026 | 23/7/2026 | Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unlock the client and… | |
| Analizada | Alta (8.8) | 0.18% | 💥 PoC | Docker Desktop | 22/5/2026 | 23/7/2026 | The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Python file, MLX-LM uses… | |
| Analizada | Alta (8.8) | 0.18% | 💥 PoC | Docker Desktop | 22/5/2026 | 23/7/2026 | The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model pulled from an OCI… | |
| Analizada | Alta (8.8) | 0.20% | — | Docker Desktop | 22/5/2026 | 23/7/2026 | The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the admin-settings configuration. However, the --use-api-socket flag adds the Docker socket mount via the… | |
| Analizada | Baja (3.5) | 0.29% | — | Mattermost Desktop | 18/5/2026 | 17/6/2026 | Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash the desktop client via invoking {{window.close()}} in the renderer context, leading to a denial of… | |
| Analizada | Media (6.5) | 0.33% | — | Mattermost Desktop | 18/5/2026 | 17/6/2026 | Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}. Mattermost Advisory ID: MMSA-2026-00618 | |
| Analizada | Crítica (9.1) | 0.35% | — | Freedesktop Gst-plugins-good | 14/5/2026 | 17/6/2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero. | |
| Analizada | Media (5.5) | 0.14% | — | Freedesktop Gst-plugins-good | 14/5/2026 | 17/6/2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero. | |
| Analizada | Alta (7.8) | 0.16% | — | Zoom Workplace Virtual Desktop Infrastructure | 13/5/2026 | 17/6/2026 | External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access. |