Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2552▼ 400 respecto a la semana anterior
Críticas / altas1318▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.49% | — | Zoom ClientsAI | 11/8/2026 | 28/8/2026 | Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access. | |
| Pendiente de análisis | Media (6.5) | 0.36% | — | Zoom ClientsAI | 11/8/2026 | 28/8/2026 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access. | |
| Aplazada | Alta (7.1) | 0.25% | — | Sprout ClientsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Boldgrid Sprout ClientsAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Stored XSS.This issue affects Sprout Clients: from n/a through <= 3.2.2. | |
| Aplazada | Alta (7.1) | 0.18% | — | Boldgrid Sprout ClientsAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Reflected XSS.This issue affects Sprout Clients: from n/a through <= 3.2.1. | |
| Aplazada | Media (6.4) | 0.34% | — | Think201 ClientsAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Think201 Clients clients allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clients: from n/a through <= 1.1.4. | |
| Aplazada | Media (6.5) | 0.36% | — | Boldgrid Sprout ClientsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Stored XSS.This issue affects Sprout Clients: from n/a through <= 3.2. | |
| Aplazada | Alta (7.7) | 0.51% | — | Amazon WorkspacesAIAmazon Appstream 2.0AIAmazon DCV ClientsAI | 15/1/2025 | 17/6/2026 | An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle. | |
| Aplazada | Media (6.5) | 0.41% | — | Think201 ClientsAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Clients clients allows Stored XSS.This issue affects Clients: from n/a through <= 1.1.4. | |
| Aplazada | Media (6.5) | 0.25% | — | Bplugins Logo Carousel Clients Logo Carousel FOR WPAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Logo Carousel – Clients logo carousel for WP responsive-client-logo-carousel-slider allows Stored XSS.This issue affects Logo Carousel – Clients logo carousel for WP: from n/a through <= 1.2. | |
| Aplazada | Alta (8.8) | 0.27% | — | Teamviewer Remote ClientsAI | 25/9/2024 | 17/6/2026 | Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers. | |
| Aplazada | Alta (8.8) | 0.41% | — | Teamviewer Remote ClientsAI | 25/9/2024 | 17/6/2026 | Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers. | |
| Modificada | Media (6.5) | 1.7% | — | Zoom Meeting SDKZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access. | |
| Modificada | Media (4.4) | 0.53% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access. | |
| Modificada | Alta (7.8) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.80% | — | Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access. | |
| Modificada | Media (6.5) | 0.80% | — | Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access. | |
| Modificada | Crítica (9.8) | 1.7% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Modificada | Media (6.5) | 0.57% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom Video Software Development KIT+1 | 14/2/2024 | 17/6/2026 | Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access. | |
| Modificada | Alta (7.8) | 0.14% | — | F5 Access Policy Manager ClientsF5 Big-ip Access Policy Manager | 2/8/2023 | 17/6/2026 | The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (5.5) | 0.14% | — | F5 Access Policy Manager ClientsF5 Big-ip Access Policy Manager | 2/8/2023 | 17/6/2026 | An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (8.8) | 0.38% | — | Valtech IDP Test Clients | 31/12/2022 | 17/6/2026 | A vulnerability was found in valtech IDP Test Client and classified as problematic. Affected by this issue is some unknown functionality of the file python-flask/main.py. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The name of the patch is… | |
| Modificada | Baja (3.3) | 0.28% | — | Zoom MeetingsZoom RoomsZoom VDI Windows Meeting Clients | 14/11/2022 | 17/6/2026 | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results… | |
| Modificada | Alta (7.8) | 0.21% | — | F5 Access Policy Manager ClientsF5 Big-ip Access Policy Manager | 5/5/2022 | 17/6/2026 | On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, the BIG-IP Edge Client Component Installer Service does not… | |
| Modificada | Alta (7.1) | 0.38% | — | Zoom MeetingsZoom Rooms FOR Conference RoomsZoom VDI Windows Meeting ClientsZoom Plugin FOR Microsoft Outlook | 28/4/2022 | 17/6/2026 | The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue… |