Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2) | 0.13% | — | Strongdm Desktop ApplicationAIStrongdm Desktop ClientAIMicrosoft WindowsAI | 29/5/2026 | 22/7/2026 | StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS… | |
| Aplazada | Alta (7) | 0.16% | — | Strongdm Macos ClientAI | 20/8/2025 | 17/6/2026 | The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system configuration by crafting a malicious JSON message. | |
| Aplazada | Alta (8.5) | 0.08% | — | Strongdm Windows ServiceAI | 20/8/2025 | 17/6/2026 | The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones. | |
| Aplazada | Alta (8.5) | 0.15% | — | StrongdmAI | 20/8/2025 | 17/6/2026 | The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation. | |
| Aplazada | Alta (8.5) | 0.11% | — | Strongdm ClientAI | 20/8/2025 | 17/6/2026 | The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition. |