Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 93 respecto a la semana anterior
Críticas / altas1464▲ 354 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 418 respecto a la semana anterior
194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Parallels DesktopAI | 14/9/2026 | 18/9/2026 | Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon… | |
| Aplazada | Alta (7.8) | 0.17% | — | Parallels RAS ClientAI | 20/8/2026 | 1/9/2026 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system… | |
| Aplazada | Alta (7.8) | 0.17% | — | Parallels RAS ClientAI | 20/8/2026 | 1/9/2026 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system… | |
| Aplazada | Alta (7.8) | 0.17% | — | Parallels RAS ClientAI | 20/8/2026 | 1/9/2026 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system… | |
| Analizada | Alta (8.8) | 1.1% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation. | |
| Analizada | Alta (7.8) | 0.32% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken, a root service writes to a file owned by a normal user. By using a hard link, an attacker can write to an arbitrary file, potentially… | |
| Analizada | Alta (7.8) | 0.28% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is deleted, a root service verifies and modifies the ownership of the snapshot files. By using a symlink, an attacker can change the ownership of… | |
| Analizada | Alta (7.8) | 0.32% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual machine is restored, the prl_vmarchiver tool decompresses the file and writes the content back to its original location using root… | |
| Aplazada | Alta (7.8) | 0.12% | — | Parallels DesktopAI | 16/3/2025 | 17/6/2026 | Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM creation routine. | |
| Analizada | Alta (7.8) | 0.41% | — | Parallels Remote Application ServerParallels | 5/2/2025 | 17/6/2026 | Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order… | |
| Aplazada | Alta (7.8) | 0.21% | — | Sunix Parallel DriverAI | 7/1/2025 | 17/6/2026 | A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These… | |
| Aplazada | Crítica (9.8) | 1.00% | — | Parallels DesktopAI | 23/9/2024 | 17/6/2026 | A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root. | |
| Modificada | Crítica (10) | 0.32% | — | Parallels Desktop | 21/6/2024 | 17/6/2026 | Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this… | |
| Modificada | Media (6.7) | 0.25% | — | Parallels Desktop | 20/6/2024 | 17/6/2026 | Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order… | |
| Modificada | Alta (7.8) | 0.29% | — | Parallels Desktop | 20/6/2024 | 17/6/2026 | Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local attackers to downgrade Parallels software on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order… | |
| Modificada | Crítica (9.8) | 0.49% | — | HPE Cray Parallel Application Launch Service | 13/6/2024 | 17/6/2026 | HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass. | |
| Analizada | Alta (7.8) | 0.21% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target… | |
| Analizada | Alta (8.3) | 0.76% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop virtio-gpu Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Parallels Desktop. User interaction is required to exploit this vulnerability in that the target in a guest system must visit a… | |
| Analizada | Alta (7.8) | 0.69% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.32% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit… | |
| Analizada | Alta (7.5) | 0.40% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Toolgate Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order… | |
| Analizada | Alta (8.2) | 1.3% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Toolgate Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to… | |
| Analizada | Alta (7.8) | 0.36% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to… | |
| Analizada | Alta (7.8) | 0.37% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to… | |
| Analizada | Alta (7.8) | 0.20% | — | Parallels Desktop | 3/5/2024 | 17/6/2026 | Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to… |