Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.47% | — | Nextcloud Team FoldersAINextcloud WorkspaceAI | 18/9/2026 | 18/9/2026 | A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management… | |
| Aplazada | Alta (8.7) | 0.35% | — | Curiosity WorkspaceAI | 16/9/2026 | 23/9/2026 | An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or… | |
| Pendiente de análisis | Media (4.4) | 0.15% | — | Citrix Workspace APP FOR WindowsAI | 11/9/2026 | 16/9/2026 | Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. | |
| Pendiente de análisis | Media (4.8) | 0.14% | — | Citrix Workspace APP FOR WindowsAI | 11/9/2026 | 16/9/2026 | Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. | |
| Pendiente de análisis | Media (5.2) | 0.18% | — | Citrix Workspace APPAI | 18/8/2026 | 28/8/2026 | External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607. | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Jenkins External Workspace Manager PluginAI | 5/8/2026 | 31/8/2026 | Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in… | |
| Analizada | Alta (7.8) | 0.18% | — | Omnissa Workspace ONE Tunnel | 8/7/2026 | 10/7/2026 | Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability. | |
| Aplazada | Alta (8.8) | 0.83% | — | Jenkins External Workspace Manager PluginAI | 24/6/2026 | 25/6/2026 | Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code… | |
| Aplazada | Media (4.8) | 0.10% | — | Genspark AI Workspace APPAI | 14/6/2026 | 24/7/2026 | A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme. The attack can only be performed from a local environment. The vendor was… | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Omnissa Workspace ONE AssistAI | 9/6/2026 | 23/7/2026 | Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability. | |
| Aplazada | Baja (2.1) | 0.28% | — | J3k0 MCP Google WorkspaceAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail Tool. Performing a manipulation results in improper access controls. It is possible to initiate the attack… | |
| Pendiente de análisis | Alta (8.5) | 0.13% | — | Amazon WorkspacesAI | 4/5/2026 | 17/6/2026 | Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading to local privilege… | |
| Pendiente de análisis | Alta (8.4) | 0.19% | — | OM WorkspaceAI | 25/3/2026 | 17/6/2026 | The installer for OM Workspace (Windows Edition) Ver 2.4 and earlier insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to execute arbitrary code with the privileges of the user invoking the installer. | |
| Analizada | Media (5.4) | 0.14% | — | Soliton Securebrowser FOR OnegateSoliton Securebrowser IISoliton Secureworkspace | 27/2/2026 | 17/6/2026 | The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges. | |
| Aplazada | Media (6.4) | 0.18% | — | Redhat Codeready WorkspacesAI | 2/12/2025 | 17/6/2026 | A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can… | |
| Analizada | Crítica (9.8) | 0.54% | — | Millensys Vision Tools Workspace | 24/11/2025 | 17/6/2026 | MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication. This page leaks plaintext database credentials, file share paths, internal license server configuration, and software update parameters. An unauthenticated attacker… | |
| Analizada | Alta (8) | 0.82% | — | IBM Planning Analytics LocalIBM Planning Analytics Workspace | 17/11/2025 | 17/6/2026 | IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences to view, read, or write arbitrary files on the system. | |
| Analizada | Media (4.3) | 0.21% | — | IBM Planning Analytics LocalIBM Planning Analytics Workspace | 17/11/2025 | 17/6/2026 | IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system. | |
| Aplazada | Media (5.3) | 0.24% | — | Omnissa Workspace ONE UEMAI | 12/11/2025 | 17/6/2026 | Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks. | |
| Aplazada | Alta (8.8) | 0.19% | — | Amazon Workspaces Client LinuxAI | 5/11/2025 | 17/6/2026 | Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces to other local users on the same client machine. Under certain circumstances, a local user may be able to extract another local user's… | |
| Aplazada | Media (5.4) | 0.19% | — | Omnissa Workspace ONE UEMAI | 11/8/2025 | 17/6/2026 | Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system information, potentially enabling enumeration of internal network resources. | |
| Aplazada | Alta (7.5) | 22% | — | Omnissa Workspace ONE UEMAI | 11/8/2025 | 17/6/2026 | Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints. | |
| Analizada | Alta (7.3) | 0.13% | — | Citrix Workspace | 17/6/2025 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | |
| Analizada | Alta (7.8) | 0.38% | — | Ivanti Workspace Control | 10/6/2025 | 17/6/2026 | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials. | |
| Analizada | Alta (7.3) | 0.36% | — | Ivanti Workspace Control | 10/6/2025 | 17/6/2026 | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password. |