Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
5105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.18% | — | Ahmad JS JS Help DeskAI | 5/10/2026 | 6/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through 4.0.0. | |
| Aplazada | Media (4.3) | 0.16% | — | Helpdesk Support Ticket System FOR WoocommerceAI | 3/10/2026 | 6/10/2026 | The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level… | |
| Aplazada | Media (5.3) | 0.20% | — | Uvdesk Support Center BundleAI | 2/10/2026 | 6/10/2026 | UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to… | |
| Pendiente de análisis | Alta (8.7) | 0.69% | — | Freedesktop Xdg-dbus-proxyAI | 2/10/2026 | 2/10/2026 | An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution… | |
| Aplazada | Baja (1.9) | 0.11% | — | Freedesktop PopplerAI | 29/9/2026 | 30/9/2026 | A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading… | |
| Aplazada | Baja (1.9) | 0.11% | — | Freedesktop PopplerAI | 29/9/2026 | 2/10/2026 | A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name:… | |
| Aplazada | Baja (2.3) | 0.21% | — | RustdeskAI | 25/9/2026 | 29/9/2026 | RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied files by guessing the… | |
| Aplazada | Media (5.3) | 0.18% | — | RustdeskAI | 25/9/2026 | 29/9/2026 | RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file transfer permissions can place files onto the host clipboard and retrieve copied files and contents… | |
| Aplazada | Alta (7.8) | 0.09% | — | Seclore Filesecure Desktop ClientAI | 25/9/2026 | 30/9/2026 | Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems. | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Gnome Remote DesktopAI | 23/9/2026 | 24/9/2026 | A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an… | |
| Aplazada | Alta (7.4) | 0.16% | — | Mrpear DesktopsmsAI | 21/9/2026 | 24/9/2026 | DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can… | |
| Aplazada | Alta (7.1) | 0.18% | — | Joplin DesktopAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.yml causes NsisUpdater.verifySignature() to skip comparison of a downloaded… | |
| Pendiente de análisis | Alta (8.3) | 0.20% | — | Telegram DesktopAI | 21/9/2026 | 22/9/2026 | Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group… | |
| Aplazada | Alta (8.6) | 0.44% | — | Uvdesk Core-frameworkAI | 21/9/2026 | 22/9/2026 | UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full… | |
| Aplazada | Media (5.3) | 0.30% | — | Uvdesk Core-frameworkAI | 21/9/2026 | 22/9/2026 | UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not… | |
| Aplazada | Media (5.1) | 0.18% | — | Uvdesk Core-frameworkAISwiftmailerAI | 21/9/2026 | 24/9/2026 | UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members… | |
| Pendiente de análisis | Baja (3.2) | 0.14% | — | Freedesktop Xdg-dbus-proxyAI | 18/9/2026 | 22/9/2026 | xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to… | |
| Aplazada | Baja (2.1) | 0.43% | — | Freedesktop PopplerAI | 18/9/2026 | 22/9/2026 | A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Baja (2.1) | 0.43% | — | Freedesktop PopplerAI | 18/9/2026 | 18/9/2026 | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is… | |
| Aplazada | Baja (2.1) | 0.59% | — | Freedesktop PopplerAI | 17/9/2026 | 22/9/2026 | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is… | |
| Aplazada | Baja (2.1) | 0.56% | — | Freedesktop PopplerAI | 17/9/2026 | 22/9/2026 | A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSample results in integer overflow. The attack may be performed from remote. The… | |
| Pendiente de análisis | Baja (2.6) | 0.22% | — | Mattermost Desktop APPAI | 17/9/2026 | 18/9/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID:… | |
| Pendiente de análisis | Baja (3.7) | 0.13% | — | Mattermost Desktop APPAI | 17/9/2026 | 18/9/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different connected server via the desktopAPI.leaveCall… | |
| Aplazada | Media (4.3) | 0.28% | — | Canva DesktopAI | 17/9/2026 | 18/9/2026 | Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session. | |
| Pendiente de análisis | Media (4.7) | 0.15% | — | Mattermost Desktop APPAI | 16/9/2026 | 17/9/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this improvement under the Mattermost responsible disclosure policy. Mattermost Advisory… |