Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.47%—Nextcloud Team FoldersAINextcloud WorkspaceAI18/9/202618/9/2026
A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management…
AplazadaAlta (8.7)0.35%—Curiosity WorkspaceAI16/9/202623/9/2026
An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or…
Pendiente de análisisMedia (4.4)0.15%—Citrix Workspace APP FOR WindowsAI11/9/202616/9/2026
Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
Pendiente de análisisMedia (4.8)0.14%—Citrix Workspace APP FOR WindowsAI11/9/202616/9/2026
Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
Pendiente de análisisMedia (5.2)0.18%—Citrix Workspace APPAI18/8/202628/8/2026
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.
Pendiente de análisisMedia (4.3)0.29%—Jenkins External Workspace Manager PluginAI5/8/202631/8/2026
Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in…
AnalizadaAlta (7.8)0.18%—Omnissa Workspace ONE Tunnel8/7/202610/7/2026
Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
AplazadaAlta (8.8)0.83%—Jenkins External Workspace Manager PluginAI24/6/202625/6/2026
Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code…
AplazadaMedia (4.8)0.10%—Genspark AI Workspace APPAI14/6/202624/7/2026
A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme. The attack can only be performed from a local environment. The vendor was…
Pendiente de análisisAlta (7.8)0.13%—Omnissa Workspace ONE AssistAI9/6/202623/7/2026
Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
AplazadaBaja (2.1)0.28%—J3k0 MCP Google WorkspaceAI1/6/202622/7/2026
A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail Tool. Performing a manipulation results in improper access controls. It is possible to initiate the attack…
Pendiente de análisisAlta (8.5)0.13%—Amazon WorkspacesAI4/5/202617/6/2026
Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading to local privilege…
Pendiente de análisisAlta (8.4)0.19%—OM WorkspaceAI25/3/202617/6/2026
The installer for OM Workspace (Windows Edition) Ver 2.4 and earlier insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to execute arbitrary code with the privileges of the user invoking the installer.
AnalizadaMedia (5.4)0.14%—Soliton Securebrowser FOR OnegateSoliton Securebrowser IISoliton Secureworkspace27/2/202617/6/2026
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.
AplazadaMedia (6.4)0.18%—Redhat Codeready WorkspacesAI2/12/202517/6/2026
A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can…
AnalizadaCrítica (9.8)0.54%—Millensys Vision Tools Workspace24/11/202517/6/2026
MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication. This page leaks plaintext database credentials, file share paths, internal license server configuration, and software update parameters. An unauthenticated attacker…
AnalizadaAlta (8)0.82%—IBM Planning Analytics LocalIBM Planning Analytics Workspace17/11/202517/6/2026
IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences to view, read, or write arbitrary files on the system.
AnalizadaMedia (4.3)0.21%—IBM Planning Analytics LocalIBM Planning Analytics Workspace17/11/202517/6/2026
IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system.
AplazadaMedia (5.3)0.24%—Omnissa Workspace ONE UEMAI12/11/202517/6/2026
Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks.
AplazadaAlta (8.8)0.19%—Amazon Workspaces Client LinuxAI5/11/202517/6/2026
Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces to other local users on the same client machine. Under certain circumstances, a local user may be able to extract another local user's…
AplazadaMedia (5.4)0.19%—Omnissa Workspace ONE UEMAI11/8/202517/6/2026
Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system information, potentially enabling enumeration of internal network resources.
AplazadaAlta (7.5)22%—Omnissa Workspace ONE UEMAI11/8/202517/6/2026
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints.
AnalizadaAlta (7.3)0.13%—Citrix Workspace17/6/202517/6/2026
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
AnalizadaAlta (7.8)0.38%—Ivanti Workspace Control10/6/202517/6/2026
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials.
AnalizadaAlta (7.3)0.36%—Ivanti Workspace Control10/6/202517/6/2026
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password.