Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.16% | — | Zilab Remote Console ServerAI | 11/2/2026 | 17/6/2026 | Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be run with… | |
| Modificada | Alta (7.8) | 1.5% | — | Vmware APP VolumesVmware Remote ConsoleVmware Tools | 23/6/2021 | 17/6/2026 | VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a… | |
| Modificada | Alta (7.8) | 0.36% | — | Vmware FusionVmware Horizon ClientVmware Remote Console | 10/7/2020 | 17/6/2026 | VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user… | |
| Modificada | Alta (7) | 0.22% | — | Vmware FusionVmware Horizon ClientVmware Remote Console | 29/5/2020 | 17/6/2026 | VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with… | |
| Analizada | Alta (7.8) | 7.3% | ⚠ Explotación activa | Vmware FusionVmware Horizon ClientVmware Remote Console | 17/3/2020 | 17/6/2026 | VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user… | |
| Modificada | Alta (7.8) | 0.39% | — | Vmware Horizon ClientVmware Remote ConsoleVmware Workstation | 16/3/2020 | 17/6/2026 | For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing configuration files for the VMware USB arbitration service was found to be writable by all users. A local user on the… | |
| Modificada | Alta (8.8) | 0.30% | — | Vmware HorizonVmware Remote ConsoleVmware WorkstationVmware Fusion+1 | 10/10/2019 | 17/6/2026 | ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5. | |
| Modificada | Media (6.5) | 1.4% | — | HP Moonshot Remote Console AdministratorHP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware | 15/2/2018 | 17/6/2026 | A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found. | |
| Modificada | Alta (10) | 70% | — | Asus Remote Console | 25/3/2008 | 16/6/2026 | Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 and 2.0.0.24 allows remote attackers to execute arbitrary code via a long string to TCP port 623. |