Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2552▼ 400 respecto a la semana anterior
Críticas / altas1318▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.3)0.49%—Zoom ClientsAI11/8/202628/8/2026
Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
Pendiente de análisisMedia (6.5)0.36%—Zoom ClientsAI11/8/202628/8/2026
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
AplazadaAlta (7.1)0.25%—Sprout ClientsAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
AplazadaMedia (6.5)0.22%—Boldgrid Sprout ClientsAI13/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Stored XSS.This issue affects Sprout Clients: from n/a through <= 3.2.2.
AplazadaAlta (7.1)0.18%—Boldgrid Sprout ClientsAI18/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Reflected XSS.This issue affects Sprout Clients: from n/a through <= 3.2.1.
AplazadaMedia (6.4)0.34%—Think201 ClientsAI3/4/202517/6/2026
Missing Authorization vulnerability in Think201 Clients clients allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clients: from n/a through <= 1.1.4.
AplazadaMedia (6.5)0.36%—Boldgrid Sprout ClientsAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Stored XSS.This issue affects Sprout Clients: from n/a through <= 3.2.
AplazadaAlta (7.7)0.51%—Amazon WorkspacesAIAmazon Appstream 2.0AIAmazon DCV ClientsAI15/1/202517/6/2026
An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.
AplazadaMedia (6.5)0.41%—Think201 ClientsAI13/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Clients clients allows Stored XSS.This issue affects Clients: from n/a through <= 1.1.4.
AplazadaMedia (6.5)0.25%—Bplugins Logo Carousel Clients Logo Carousel FOR WPAI5/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Logo Carousel – Clients logo carousel for WP responsive-client-logo-carousel-slider allows Stored XSS.This issue affects Logo Carousel – Clients logo carousel for WP: from n/a through <= 1.2.
AplazadaAlta (8.8)0.27%—Teamviewer Remote ClientsAI25/9/202417/6/2026
Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers.
AplazadaAlta (8.8)0.41%—Teamviewer Remote ClientsAI25/9/202417/6/2026
Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers.
ModificadaMedia (6.5)1.7%—Zoom Meeting SDKZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.
ModificadaMedia (4.4)0.53%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
ModificadaAlta (7.8)0.27%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaMedia (6.5)0.80%—Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaMedia (6.5)0.80%—Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaCrítica (9.8)1.7%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.
ModificadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom Video Software Development KIT+114/2/202417/6/2026
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (7.8)0.14%—F5 Access Policy Manager ClientsF5 Big-ip Access Policy Manager2/8/202317/6/2026
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (5.5)0.14%—F5 Access Policy Manager ClientsF5 Big-ip Access Policy Manager2/8/202317/6/2026
An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaAlta (8.8)0.38%—Valtech IDP Test Clients31/12/202217/6/2026
A vulnerability was found in valtech IDP Test Client and classified as problematic. Affected by this issue is some unknown functionality of the file python-flask/main.py. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The name of the patch is…
ModificadaBaja (3.3)0.28%—Zoom MeetingsZoom RoomsZoom VDI Windows Meeting Clients14/11/202217/6/2026
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results…
ModificadaAlta (7.8)0.21%—F5 Access Policy Manager ClientsF5 Big-ip Access Policy Manager5/5/202217/6/2026
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, the BIG-IP Edge Client Component Installer Service does not…
ModificadaAlta (7.1)0.38%—Zoom MeetingsZoom Rooms FOR Conference RoomsZoom VDI Windows Meeting ClientsZoom Plugin FOR Microsoft Outlook28/4/202217/6/2026
The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue…