Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
3978 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.69% | — | Freedesktop Xdg-dbus-proxyAI | 2/10/2026 | 2/10/2026 | An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution… | |
| Aplazada | Baja (1.9) | 0.11% | — | Freedesktop PopplerAI | 29/9/2026 | 30/9/2026 | A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading… | |
| Aplazada | Baja (1.9) | 0.11% | — | Freedesktop PopplerAI | 29/9/2026 | 2/10/2026 | A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name:… | |
| Aplazada | Alta (7.8) | 0.09% | — | Seclore Filesecure Desktop ClientAI | 25/9/2026 | 30/9/2026 | Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems. | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Gnome Remote DesktopAI | 23/9/2026 | 24/9/2026 | A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an… | |
| Aplazada | Alta (7.4) | 0.16% | — | Mrpear DesktopsmsAI | 21/9/2026 | 24/9/2026 | DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can… | |
| Aplazada | Alta (7.1) | 0.18% | — | Joplin DesktopAI | 21/9/2026 | 23/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.yml causes NsisUpdater.verifySignature() to skip comparison of a downloaded… | |
| Pendiente de análisis | Alta (8.3) | 0.20% | — | Telegram DesktopAI | 21/9/2026 | 22/9/2026 | Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group… | |
| Pendiente de análisis | Baja (3.2) | 0.14% | — | Freedesktop Xdg-dbus-proxyAI | 18/9/2026 | 22/9/2026 | xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to… | |
| Aplazada | Baja (2.1) | 0.43% | — | Freedesktop PopplerAI | 18/9/2026 | 22/9/2026 | A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Baja (2.1) | 0.43% | — | Freedesktop PopplerAI | 18/9/2026 | 18/9/2026 | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is… | |
| Aplazada | Baja (2.1) | 0.59% | — | Freedesktop PopplerAI | 17/9/2026 | 22/9/2026 | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is… | |
| Aplazada | Baja (2.1) | 0.56% | — | Freedesktop PopplerAI | 17/9/2026 | 22/9/2026 | A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSample results in integer overflow. The attack may be performed from remote. The… | |
| Pendiente de análisis | Baja (2.6) | 0.22% | — | Mattermost Desktop APPAI | 17/9/2026 | 18/9/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID:… | |
| Pendiente de análisis | Baja (3.7) | 0.13% | — | Mattermost Desktop APPAI | 17/9/2026 | 18/9/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different connected server via the desktopAPI.leaveCall… | |
| Aplazada | Media (4.3) | 0.28% | — | Canva DesktopAI | 17/9/2026 | 18/9/2026 | Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session. | |
| Pendiente de análisis | Media (4.7) | 0.15% | — | Mattermost Desktop APPAI | 16/9/2026 | 17/9/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this improvement under the Mattermost responsible disclosure policy. Mattermost Advisory… | |
| Pendiente de análisis | Alta (7.7) | 0.34% | — | Oracle WEB Applications Desktop IntegratorAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Web Applications… | |
| Pendiente de análisis | Media (6.5) | 0.34% | — | Oracle WEB Applications Desktop IntegratorAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications… | |
| Pendiente de análisis | Media (5.1) | 0.18% | — | Newell Brands Dymo Connect DesktopAI | 15/9/2026 | 22/9/2026 | The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension… | |
| Pendiente de análisis | Crítica (9.4) | 0.20% | — | Apple MacosAIDocker DesktopAI | 15/9/2026 | 16/9/2026 | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host… | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Parallels DesktopAI | 14/9/2026 | 18/9/2026 | Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon… | |
| Aplazada | Alta (8.4) | 0.18% | — | Rakuten Kobo Desktop ApplicationAI | 14/9/2026 | 16/9/2026 | The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation. | |
| Aplazada | Alta (8.6) | 0.19% | — | Autodesk Fusion DesktopAI | 10/9/2026 | 11/9/2026 | A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing… | |
| Analizada | Alta (7.5) | 0.64% | — | Microsoft Remote Desktop Client | 8/9/2026 | 16/9/2026 | Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network. |