Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.09% | — | Seclore Filesecure Desktop ClientAI | 25/9/2026 | 30/9/2026 | Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems. | |
| Analizada | Alta (7.5) | 0.64% | — | Microsoft Remote Desktop Client | 8/9/2026 | 16/9/2026 | Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Alta (7.3) | 0.16% | — | Arksigner Software AND Hardware Industry AND Trade INC Arksigner Desktop ClientAI | 28/7/2026 | 28/7/2026 | Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Alta (7.5) | 0.61% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.5) | 0.61% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (7.5) | 0.47% | — | Microsoft Remote Desktop ClientMicrosoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+3 | 9/6/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (7.5) | 0.47% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Pendiente de análisis | Baja (2) | 0.13% | — | Strongdm Desktop ApplicationAIStrongdm Desktop ClientAIMicrosoft WindowsAI | 29/5/2026 | 22/7/2026 | StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS… | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 14/4/2026 | 25/9/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.60% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+14 | 14/10/2025 | 17/6/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 8/7/2025 | 17/6/2026 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 1.4% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 10/6/2025 | 17/6/2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8) | 1.5% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 8/4/2025 | 17/6/2026 | Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 3.2% | — | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+12 | 11/3/2025 | 17/6/2026 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.4) | 1.5% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 12/12/2024 | 17/6/2026 | Remote Desktop Client Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 1.3% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+12 | 13/8/2024 | 17/6/2026 | Clipboard Virtual Channel Extension Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 0.97% | — | Ivanti Pulse Secure Desktop ClientIvanti Pulse Secure Installer ServiceIvanti Secure Access Client | 3/5/2024 | 17/6/2026 | Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pulse Secure Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Alta (8.8) | 1.3% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+9 | 14/6/2023 | 17/6/2026 | Remote Desktop Client Remote Code Execution Vulnerability | |
| Analizada | Media (6.5) | 1.2% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+4 | 14/6/2023 | 17/6/2026 | Windows Remote Desktop Security Feature Bypass Vulnerability | |
| Analizada | Media (6.5) | 2.1% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+10 | 11/4/2023 | 17/6/2026 | Remote Desktop Protocol Client Information Disclosure Vulnerability |