Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3979 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.14% | — | Docker DesktopAI | 26/9/2025 | 17/6/2026 | In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-container-isolation/ ) enabled, an administrator can utilize the command restrictions feature… | |
| Aplazada | Alta (7.8) | 0.17% | — | Solidworks EdrawingsAISolidworks DesktopAI | 17/9/2025 | 25/9/2026 | An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary code while opening a specially crafted PAR file. | |
| Aplazada | Baja (2.7) | 0.41% | — | Element WEBAIElement DesktopAIMatrix React SDKAI | 16/9/2025 | 1/10/2026 | Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11.112 have insufficient validation of room predecessor links, allowing a remote attacker to attempt to impermanently replace a room's entry in the room list with an unrelated attacker-supplied room.… | |
| Analizada | Media (6.5) | 0.26% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 9/9/2025 | 17/6/2026 | Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (4.3) | 0.20% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 9/9/2025 | 17/6/2026 | Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access. | |
| Analizada | Alta (7.4) | 0.31% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 9/9/2025 | 17/6/2026 | Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.5) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 9/9/2025 | 17/6/2026 | Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.32% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 9/9/2025 | 17/6/2026 | Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.3) | 0.29% | — | HP Poly Lens Desktop | 9/9/2025 | 17/6/2026 | A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privileges being granted. | |
| Analizada | Alta (8.4) | 1.1% | 💥 PoC | Figma Desktop | 3/9/2025 | 17/6/2026 | Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS commands by setting a crafted build field in the plugin's manifest.json. This field is passed to child_process.exec without validation, leading to possible RCE. NOTE:… | |
| Aplazada | Alta (8.4) | 0.51% | 💥 Exploit | AOL DesktopAI | 20/8/2025 | 16/6/2026 | AOL Desktop 9.6 contains a buffer overflow vulnerability in its Tool\rich.rct component when parsing .rtx files. By embedding an overly long string in a hyperlink tag, an attacker can trigger a stack-based buffer overflow due to the use of unsafe strcpy operations. This allows remote attackers to execute arbitrary… | |
| Aplazada | Crítica (9.3) | 1.9% | 💥 Exploit | Docker DesktopAI | 20/8/2025 | 17/6/2026 | A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Container Isolation (ECI) enabled, and with or without the "Expose daemon on… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Screenshot-desktopAI | 19/8/2025 | 17/6/2026 | screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is passed into the format option of the screenshot function, it is interpolated into a shell command without sanitization. This results in arbitrary command execution with… | |
| Analizada | Alta (8.8) | 0.62% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 12/8/2025 | 17/6/2026 | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access | |
| Analizada | Media (5.1) | 0.11% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 12/8/2025 | 17/6/2026 | Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access. | |
| Analizada | Crítica (9.8) | 0.57% | — | Axosoft Gitkraken Desktop | 4/8/2025 | 17/6/2026 | The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode,… | |
| Modificada | Media (6.5) | 0.32% | 💥 PoC | Freedesktop Poppler | 4/8/2025 | 5/7/2026 | An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS). | |
| Aplazada | Media (5.4) | 0.32% | — | Lbry-desktopAI | 23/7/2025 | 17/6/2026 | A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages. | |
| Aplazada | Alta (7.8) | 0.18% | — | Solidworks EdrawingsAISolidworks DesktopAI | 15/7/2025 | 17/6/2026 | Use After Free vulnerability exists in the IPT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted IPT file. | |
| Aplazada | Alta (7.8) | 0.19% | — | Solidworks EdrawingsAISolidworks DesktopAI | 15/7/2025 | 17/6/2026 | Use After Free vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted JT file. | |
| Aplazada | Alta (7.8) | 0.19% | — | Solidworks EdrawingsAISolidworks DesktopAI | 15/7/2025 | 17/6/2026 | Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted CATPRODUCT file. | |
| Analizada | Media (5.7) | 0.66% | — | Ivanti Desktop & Server Management | 12/7/2025 | 17/6/2026 | A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials. | |
| Analizada | Crítica (9.1) | 0.27% | — | Zoom Workplace Desktop | 10/7/2025 | 17/6/2026 | Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access. | |
| Analizada | Alta (7.3) | 0.24% | 💥 PoC | Citrix Virtual Apps AND Desktops | 8/7/2025 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS | |
| Analizada | Crítica (9.6) | 1.1% | — | Adobe Connect Desktop Application | 8/7/2025 | 17/6/2026 | Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interaction and scope is changed. |