Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.17%—Adobe Creative Cloud Desktop Application14/7/202628/8/2026
Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is…
AnalizadaAlta (7.8)0.23%—Adobe Creative Cloud Desktop Application14/7/202628/8/2026
Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
ModificadaAlta (7.1)0.30%—Adobe Creative Cloud Desktop Application13/6/202417/6/2026
Creative Cloud Desktop versions 6.1.0.587 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to load and execute malicious libraries, leading to arbitrary file delete. Exploitation of this issue…
AplazadaMedia (6.3)0.47%—Vesystem Cloud DesktopAI15/4/202417/6/2026
A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue affects some unknown processing of the file /Public/webuploader/0.1.5/server/fileupload2.php. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely.…
AplazadaMedia (6.3)0.47%—Vesystem Cloud DesktopAI15/4/202417/6/2026
A vulnerability classified as critical was found in Vesystem Cloud Desktop up to 20240408. This vulnerability affects unknown code of the file /Public/webuploader/0.1.5/server/fileupload.php. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been…
ModificadaAlta (7)2.2%—Adobe Creative Cloud Desktop Application16/2/202217/6/2026
Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must download a malicious DLL file. The…
ModificadaAlta (7.8)2.7%—Owncloud Desktop ClientFedoraproject Fedora15/1/202217/6/2026
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
ModificadaAlta (7.8)2.2%—Adobe Creative Cloud Desktop Application23/11/202117/6/2026
Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of SYSTEM . An attacker must first obtain the…
ModificadaMedia (4.2)1.2%—Adobe Creative Cloud Desktop Application18/11/202117/6/2026
Adobe Creative Cloud version 5.5 (and earlier) are affected by an Application denial of service vulnerability in the Creative Cloud Desktop installer. An authenticated attacker with root privileges could leverage this vulnerability to achieve denial of service by planting a malicious file on the victim's local…
ModificadaAlta (7.8)0.52%—Adobe Creative Cloud Desktop Application29/9/202117/6/2026
Adobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulnerability that could allow a normal user to delete the OOBE directory and get permissions of any directory under the administrator authority.
ModificadaAlta (7.4)0.49%—Adobe Creative Cloud Desktop Application27/9/202117/6/2026
Adobe Creative Cloud Desktop Application version 5.4 (and earlier) is affected by a file handling vulnerability that could allow an attacker to arbitrarily overwrite a file. Exploitation of this issue requires local access, administrator privileges and user interaction.
ModificadaMedia (6.1)0.49%—Adobe Creative Cloud Desktop Application24/8/202117/6/2026
Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Insecure temporary file creation vulnerability. An attacker could leverage this vulnerability to cause arbitrary file overwriting in the context of the current user. Exploitation of this issue requires physical interaction…
ModificadaAlta (7.8)2.7%—Adobe Creative Cloud Desktop Application24/8/202117/6/2026
Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
ModificadaMedia (6.5)1.1%—Adobe Creative Cloud Desktop Application12/3/202117/6/2026
Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability in CCXProcess that could allow an attacker to achieve arbitrary code execution in the process of the current user. Exploitation of this issue requires user interaction
ModificadaAlta (7.8)2.6%—Adobe Creative Cloud Desktop Application12/3/202117/6/2026
Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a local privilege escalation vulnerability that could allow an attacker to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction.
ModificadaMedia (6.1)0.62%—Adobe Creative Cloud Desktop Application12/3/202117/6/2026
Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a file handling vulnerability that could allow an attacker to cause arbitrary file overwriting. Exploitation of this issue requires physical access and user interaction.
ModificadaAlta (7.8)0.77%—Owncloud Desktop Client26/2/202117/6/2026
ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.
ModificadaCrítica (9.8)4.3%—Adobe Creative Cloud Desktop Application17/7/202017/6/2026
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to arbitrary file system write.
ModificadaCrítica (9.8)4.0%—Adobe Creative Cloud Desktop Application17/7/202017/6/2026
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.
ModificadaCrítica (9.8)3.6%—Adobe Creative Cloud Desktop Application17/7/202017/6/2026
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to privilege escalation.
ModificadaAlta (8.4)0.53%—Owncloud Desktop Client23/1/201717/6/2026
ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special path" in the C: drive.
ModificadaMedia (5.1)0.67%—Owncloud Desktop ClientQT26/10/201517/6/2026
ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which makes it easier for remote attackers to conduct man-in-the-middle (MITM) attacks by leveraging a server using a self-signed certificate. NOTE:…
ModificadaBaja (2.6)0.83%—Owncloud Desktop Client26/10/201517/6/2026
ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by leveraging a self-signed certificate and a connection to a server…