Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

3978 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.69%—Freedesktop Xdg-dbus-proxyAI2/10/20262/10/2026
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution…
AplazadaBaja (1.9)0.11%—Freedesktop PopplerAI29/9/202630/9/2026
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading…
AplazadaBaja (1.9)0.11%—Freedesktop PopplerAI29/9/20262/10/2026
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name:…
AplazadaAlta (7.8)0.09%—Seclore Filesecure Desktop ClientAI25/9/202630/9/2026
Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems.
Pendiente de análisisAlta (7.5)0.79%—Gnome Remote DesktopAI23/9/202624/9/2026
A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an…
AplazadaAlta (7.4)0.16%—Mrpear DesktopsmsAI21/9/202624/9/2026
DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can…
AplazadaAlta (7.1)0.18%—Joplin DesktopAI21/9/202623/9/2026
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.yml causes NsisUpdater.verifySignature() to skip comparison of a downloaded…
Pendiente de análisisAlta (8.3)0.20%—Telegram DesktopAI21/9/202622/9/2026
Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group…
Pendiente de análisisBaja (3.2)0.14%—Freedesktop Xdg-dbus-proxyAI18/9/202622/9/2026
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to…
AplazadaBaja (2.1)0.43%—Freedesktop PopplerAI18/9/202622/9/2026
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be…
AplazadaBaja (2.1)0.43%—Freedesktop PopplerAI18/9/202618/9/2026
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is…
AplazadaBaja (2.1)0.59%—Freedesktop PopplerAI17/9/202622/9/2026
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is…
AplazadaBaja (2.1)0.56%—Freedesktop PopplerAI17/9/202622/9/2026
A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSample results in integer overflow. The attack may be performed from remote. The…
Pendiente de análisisBaja (2.6)0.22%—Mattermost Desktop APPAI17/9/202618/9/2026
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID:…
Pendiente de análisisBaja (3.7)0.13%—Mattermost Desktop APPAI17/9/202618/9/2026
Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different connected server via the desktopAPI.leaveCall…
AplazadaMedia (4.3)0.28%—Canva DesktopAI17/9/202618/9/2026
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
Pendiente de análisisMedia (4.7)0.15%—Mattermost Desktop APPAI16/9/202617/9/2026
Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this improvement under the Mattermost responsible disclosure policy. Mattermost Advisory…
Pendiente de análisisAlta (7.7)0.34%—Oracle WEB Applications Desktop IntegratorAIOracle E-business SuiteAI15/9/202616/9/2026
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Web Applications…
Pendiente de análisisMedia (6.5)0.34%—Oracle WEB Applications Desktop IntegratorAIOracle E-business SuiteAI15/9/202616/9/2026
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications…
Pendiente de análisisMedia (5.1)0.18%—Newell Brands Dymo Connect DesktopAI15/9/202622/9/2026
The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension…
Pendiente de análisisCrítica (9.4)0.20%—Apple MacosAIDocker DesktopAI15/9/202616/9/2026
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host…
Pendiente de análisisAlta (7.8)0.17%—Parallels DesktopAI14/9/202618/9/2026
Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon…
AplazadaAlta (8.4)0.18%—Rakuten Kobo Desktop ApplicationAI14/9/202616/9/2026
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.
AplazadaAlta (8.6)0.19%—Autodesk Fusion DesktopAI10/9/202611/9/2026
A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing…
AnalizadaAlta (7.5)0.64%—Microsoft Remote Desktop Client8/9/202616/9/2026
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.