Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

3978 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.82%—Microsoft Remote Desktop Client8/9/202622/9/2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft Remote Desktop Client8/9/202622/9/2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.86%—Microsoft Remote Desktop Client8/9/202622/9/2026
Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7)0.28%—Microsoft Power Automate FOR Desktop8/9/202629/9/2026
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
AplazadaAlta (8.6)0.17%—Bilibili DesktopAI5/9/202623/9/2026
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the…
AplazadaMedia (6.9)0.41%—Lightstar Smartit Desktop ManagerAILightstar Smartit AgentAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.
AplazadaCrítica (9.3)0.63%—Lightstar Smartit Desktop ManagerAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
AplazadaAlta (8.7)0.33%—Lightstar Smartit Desktop ManagerAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.
AplazadaCrítica (9.3)0.63%—Lightstar Smartit Desktop ManagerAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
En análisisCrítica (9.8)0.37%—Openai Codex DesktopAIGITAI1/9/20262/9/2026
OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an…
En análisisAlta (7.3)0.11%—Openai Codex CLIAIOpenai Codex DesktopAIGit-scm GITAI1/9/20262/9/2026
OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-local core.fsmonitor setting. If a user opens or uses an attacker-prepared repository whose preserved .git/config sets core.fsmonitor to an…
En análisisAlta (8.8)0.30%—Openai Codex CLIAIOpenai Codex DesktopAIMicrosoft PowershellAI1/9/20262/9/2026
OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex…
En análisisAlta (7.3)0.11%—Openai Codex DesktopAI1/9/20263/9/2026
OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can…
AplazadaCrítica (9.8)0.93%—Bilibili DesktopAI27/8/20261/9/2026
An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.
AplazadaCrítica (10)0.78%—Ui-tars-desktop Mcp-http-serverAIAgent-infra Mcp-server-commandsAIAgent-infra Mcp-server-filesystemAI27/8/202623/9/2026
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a…
AplazadaAlta (7.5)0.27%—Teamviewer DesktopAI26/8/20261/9/2026
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to…
Pendiente de análisisMedia (4.3)0.15%—Devolutions Remote Desktop ManagerAIIronvncAI24/8/202628/8/2026
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
AnalizadaBaja (3.3)0.13%—Mattermost Desktop17/8/202619/8/2026
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity…
Pendiente de análisisAlta (7.7)0.63%—Docker DesktopAIMicrosoft DEV Containers CLIAIAnysphere CursorAI11/8/20269/9/2026
Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home…
Pendiente de análisisAlta (7.8)0.17%—Freedesktop Udisks2AI6/8/20268/9/2026
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary…
Pendiente de análisisAlta (7.5)0.52%—Gnome Remote DesktopAIRedhat Enterprise LinuxAI31/7/202613/8/2026
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP…
AplazadaAlta (7.3)0.16%—Arksigner Software AND Hardware Industry AND Trade INC Arksigner Desktop ClientAI28/7/202628/7/2026
Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026.
AplazadaCrítica (9.4)0.56%—Siyuan DesktopAI27/7/202617/9/2026
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access…
AplazadaAlta (8.7)1.1%—Nitroshare DesktopAI27/7/202628/7/2026
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit…
Pendiente de análisisMedia (5.5)0.14%—Systemd-homedAIFreedesktop AccountsserviceAI24/7/202624/7/2026
A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.