Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
5106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.14% | — | GFI Helpdesk | 20/4/2026 | 17/6/2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and EditSubmit() before being rendered by View_Step.RenderViewSteps(). An authenticated staff member can inject arbitrary… | |
| Analizada | Media (4.8) | 0.15% | — | GFI Helpdesk | 20/4/2026 | 17/6/2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create() without HTML sanitization and subsequently rendered unsanitized by View_Language.RenderGrid(). An authenticated… | |
| Analizada | Media (4.8) | 0.15% | — | GFI Helpdesk | 20/4/2026 | 17/6/2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyname POST parameter without HTML sanitization. Attackers can inject malicious… | |
| Pendiente de análisis | Media (4.3) | 0.17% | — | Vision HelpdeskAI | 16/4/2026 | 17/6/2026 | Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id. | |
| Pendiente de análisis | Media (6.2) | 0.16% | — | Onlyoffice DesktopeditorsAI | 16/4/2026 | 17/6/2026 | In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges. | |
| Pendiente de análisis | Alta (8.7) | 0.29% | — | HP DeskjetAI | 15/4/2026 | 17/6/2026 | Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for Devices (WSD) scan requests are improperly validated and handled by the MFP. WSD Scan is a Microsoft Windows–based network scanning protocol that allows a PC to discover… | |
| Analizada | Alta (8.7) | 0.70% | — | Adobe ConnectAdobe Connect Desktop Application | 14/4/2026 | 28/8/2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's… | |
| Analizada | Crítica (9.3) | 1.8% | — | Adobe ConnectAdobe Connect Desktop Application | 14/4/2026 | 28/8/2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated… | |
| Analizada | Media (6.1) | 0.43% | — | Adobe ConnectAdobe Connect Desktop Application | 14/4/2026 | 28/8/2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed. | |
| Analizada | Crítica (9.6) | 1.9% | — | Adobe ConnectAdobe Connect Desktop Application | 14/4/2026 | 28/8/2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact… | |
| Analizada | Crítica (9.3) | 0.74% | — | Adobe ConnectAdobe Connect Desktop Application | 14/4/2026 | 28/8/2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this… | |
| Analizada | Crítica (9.3) | 0.74% | — | Adobe ConnectAdobe Connect Desktop Application | 14/4/2026 | 28/8/2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this… | |
| Analizada | Crítica (9.3) | 0.74% | — | Adobe ConnectAdobe Connect Desktop Application | 14/4/2026 | 28/8/2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this… | |
| Analizada | Media (6.1) | 0.28% | — | Adobe ConnectAdobe Connect Desktop Application | 14/4/2026 | 28/8/2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 14/4/2026 | 25/9/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.1) | 0.29% | — | Autodesk Fusion | 14/4/2026 | 17/6/2026 | A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or… | |
| Analizada | Alta (7.1) | 0.29% | — | Autodesk Fusion | 14/4/2026 | 17/6/2026 | A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current… | |
| Analizada | Alta (7.1) | 0.29% | — | Autodesk Fusion | 14/4/2026 | 17/6/2026 | A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute… | |
| Aplazada | Alta (8.6) | 0.16% | — | Faleemi Desktop SoftwareAI | 12/4/2026 | 17/6/2026 | Faleemi Desktop Software 1.8 contains a local buffer overflow vulnerability in the System Setup dialog that allows attackers to bypass DEP protections through structured exception handling exploitation. Attackers can inject a crafted payload into the Save Path for Snapshot and Record file field to trigger a buffer… | |
| Analizada | Media (6.3) | 0.16% | — | Flatpak Xdg-desktop-portal | 11/4/2026 | 17/6/2026 | Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash. | |
| Pendiente de análisis | Alta (7.1) | 0.13% | — | Tmds Dbus ProtocolAIFreedesktop DbusAI | 9/4/2026 | 17/6/2026 | Tmds.DBus provides .NET libraries for working with D-Bus from .NET. Tmds.DBus and Tmds.DBus.Protocol are vulnerable to malicious D-Bus peers. A peer on the same bus can spoof signals by impersonating the owner of a well-known name, exhaust system resources or cause file descriptor spillover by sending messages with an… | |
| Analizada | Baja (2.7) | 0.27% | — | Canonical Ubuntu Desktop Provision | 9/4/2026 | 7/10/2026 | In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs. | |
| Aplazada | Media (5.3) | 0.26% | — | THE Publisher Desk ADS TXTAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in PublisherDesk The Publisher Desk ads.txt the-publisher-desk-ads-txt allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Publisher Desk ads.txt: from n/a through <= 1.5.0. | |
| Modificada | Crítica (9.1) | 0.73% | — | Linuxfoundation Podman Desktop | 7/4/2026 | 24/7/2026 | Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limits and timeouts, an… | |
| Analizada | Media (5.5) | 0.14% | — | Hitachi JOB Management Partner 1/it Desktop Management-managerHitachi Jp1/it Desktop Management 2-managerHitachi Jp1/it Desktop Management 2-operations DirectorHitachi Jp1/netm/dm Manager+1 | 7/4/2026 | 17/6/2026 | Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management -… |