Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.41% | — | Parallels Remote Application ServerParallels | 5/2/2025 | 17/6/2026 | Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order… | |
| Analizada | Crítica (9.8) | 0.74% | — | Gnome-remote-desktopCanonical Ubuntu Linux | 31/1/2025 | 17/6/2026 | Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default. | |
| Aplazada | Crítica (9.8) | 2.1% | 💥 Exploit | Emote Interactive Remote Mouse ServerAI | 28/1/2025 | 17/6/2026 | Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and… | |
| Analizada | Media (5.3) | 0.23% | — | Etictelecom Remote Access Server Firmware | 17/1/2025 | 17/6/2026 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in get view method under view parameter. The ETIC RAS web server uses dynamic pages that get their input from the client side and reflect the input in their response to the client. | |
| Analizada | Media (4.8) | 0.22% | — | Etictelecom Remote Access Server Firmware | 17/1/2025 | 17/6/2026 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in the method parameter. The ETIC RAS web server uses dynamic pages that gets their input from the client side and reflects the input in its response to the client. | |
| Analizada | Media (6.1) | 0.24% | — | Etictelecom Remote Access Server Firmware | 17/1/2025 | 17/6/2026 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal. An attacker can access the ETIC RAS web portal and view the HTML code, which is configured to be hidden, thus allowing a connection to the ETIC RAS ssh server, which could enable an attacker to… | |
| Analizada | Media (4.8) | 0.22% | — | Etictelecom Remote Access Server Firmware | 17/1/2025 | 17/6/2026 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting in the appliance site name. The ETIC RAS web server saves the site name and then presents it to the administrators in a few different pages. | |
| Analizada | Media (6.3) | 0.18% | — | Etictelecom Remote Access Server Firmware | 17/1/2025 | 17/6/2026 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the… | |
| Analizada | Alta (7.2) | 14% | ⚠ Explotación activa | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 18/12/2024 | 17/6/2026 | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user. | |
| Aplazada | Media (4.3) | 0.29% | — | Keyfactor Remote File OrchestratorAI | 18/12/2024 | 17/6/2026 | Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information could be exposed at the debug logging level. | |
| Analizada | Crítica (9.8) | 87% | ⚠ Explotación activa💥 Exploit | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 17/12/2024 | 17/6/2026 | A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user. | |
| Analizada | Alta (8.4) | 1.5% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 12/12/2024 | 17/6/2026 | Remote Desktop Client Remote Code Execution Vulnerability | |
| Analizada | Alta (8.1) | 0.60% | — | Devolutions Remote Desktop Manager | 4/12/2024 | 17/6/2026 | Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested. | |
| Modificada | Crítica (9.8) | 56% | — | HPE Insight Remote Support | 27/11/2024 | 17/6/2026 | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution. | |
| Analizada | Alta (7.5) | 84% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | |
| Analizada | Alta (7.5) | 47% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | |
| Analizada | Crítica (9.8) | 0.72% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code. | |
| Analizada | Alta (7.5) | 1.5% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | |
| Analizada | Media (4.3) | 0.55% | — | Devolutions Remote Desktop Manager | 25/11/2024 | 17/6/2026 | Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature. | |
| Analizada | Media (5.4) | 0.53% | — | Devolutions Remote Desktop Manager | 25/11/2024 | 17/6/2026 | Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching. | |
| Analizada | Media (5.4) | 0.67% | — | Devolutions Remote Desktop Manager | 25/11/2024 | 17/6/2026 | Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions. | |
| Aplazada | Alta (7.5) | 0.47% | — | Holy Stone Remote ID Module Hsrid01AIHoly Stone Drone GO2AI | 17/11/2024 | 17/6/2026 | Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) via multiple read operations on the ASTM Remote ID (0xFFFA) GATT. | |
| Analizada | Alta (7.1) | 0.43% | — | Microsoft Remote SSH | 12/11/2024 | 17/6/2026 | Visual Studio Code Remote Extension Elevation of Privilege Vulnerability | |
| Aplazada | Media (5.2) | 0.14% | — | Jamf PROAIJamf Remote AssistAI | 22/10/2024 | 17/6/2026 | A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges to root on MacOS systems. | |
| Modificada | Media (5.5) | 0.15% | — | Devolutions Remote Desktop Manager | 25/9/2024 | 17/6/2026 | An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions |