Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.41%—Parallels Remote Application ServerParallels5/2/202517/6/2026
Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order…
AnalizadaCrítica (9.8)0.74%—Gnome-remote-desktopCanonical Ubuntu Linux31/1/202517/6/2026
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
AplazadaCrítica (9.8)2.1%💥 ExploitEmote Interactive Remote Mouse ServerAI28/1/202517/6/2026
Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and…
AnalizadaMedia (5.3)0.23%—Etictelecom Remote Access Server Firmware17/1/202517/6/2026
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in get view method under view parameter. The ETIC RAS web server uses dynamic pages that get their input from the client side and reflect the input in their response to the client.
AnalizadaMedia (4.8)0.22%—Etictelecom Remote Access Server Firmware17/1/202517/6/2026
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in the method parameter. The ETIC RAS web server uses dynamic pages that gets their input from the client side and reflects the input in its response to the client.
AnalizadaMedia (6.1)0.24%—Etictelecom Remote Access Server Firmware17/1/202517/6/2026
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal. An attacker can access the ETIC RAS web portal and view the HTML code, which is configured to be hidden, thus allowing a connection to the ETIC RAS ssh server, which could enable an attacker to…
AnalizadaMedia (4.8)0.22%—Etictelecom Remote Access Server Firmware17/1/202517/6/2026
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting in the appliance site name. The ETIC RAS web server saves the site name and then presents it to the administrators in a few different pages.
AnalizadaMedia (6.3)0.18%—Etictelecom Remote Access Server Firmware17/1/202517/6/2026
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the…
AnalizadaAlta (7.2)14%⚠ Explotación activaBeyondtrust Privileged Remote AccessBeyondtrust Remote Support18/12/202417/6/2026
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
AplazadaMedia (4.3)0.29%—Keyfactor Remote File OrchestratorAI18/12/202417/6/2026
Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information could be exposed at the debug logging level.
AnalizadaCrítica (9.8)87%⚠ Explotación activa💥 ExploitBeyondtrust Privileged Remote AccessBeyondtrust Remote Support17/12/202417/6/2026
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
AnalizadaAlta (8.4)1.5%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+1312/12/202417/6/2026
Remote Desktop Client Remote Code Execution Vulnerability
AnalizadaAlta (8.1)0.60%—Devolutions Remote Desktop Manager4/12/202417/6/2026
Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested.
ModificadaCrítica (9.8)56%—HPE Insight Remote Support27/11/202417/6/2026
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
AnalizadaAlta (7.5)84%—HPE Insight Remote Support26/11/202417/6/2026
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
AnalizadaAlta (7.5)47%—HPE Insight Remote Support26/11/202417/6/2026
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
AnalizadaCrítica (9.8)0.72%—HPE Insight Remote Support26/11/202417/6/2026
A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.
AnalizadaAlta (7.5)1.5%—HPE Insight Remote Support26/11/202417/6/2026
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
AnalizadaMedia (4.3)0.55%—Devolutions Remote Desktop Manager25/11/202417/6/2026
Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.
AnalizadaMedia (5.4)0.53%—Devolutions Remote Desktop Manager25/11/202417/6/2026
Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.
AnalizadaMedia (5.4)0.67%—Devolutions Remote Desktop Manager25/11/202417/6/2026
Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.
AplazadaAlta (7.5)0.47%—Holy Stone Remote ID Module Hsrid01AIHoly Stone Drone GO2AI17/11/202417/6/2026
Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) via multiple read operations on the ASTM Remote ID (0xFFFA) GATT.
AnalizadaAlta (7.1)0.43%—Microsoft Remote SSH12/11/202417/6/2026
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
AplazadaMedia (5.2)0.14%—Jamf PROAIJamf Remote AssistAI22/10/202417/6/2026
A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges to root on MacOS systems.
ModificadaMedia (5.5)0.15%—Devolutions Remote Desktop Manager25/9/202417/6/2026
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
Orbitaley — Vulnerabilidades