Vulnerabilities
Summary — last 7 days
New vulnerabilities3,047▲ 440 vs. last week
Critical / high1,452▲ 212 vs. last week
New active exploitation (KEV)8▼ 2 vs. last week
Unscored (no CVSS)365▲ 151 vs. last week
3,977 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (1.9) | 0.11% | — | Freedesktop PopplerAI | 9/29/2026 | 9/30/2026 | A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading… | |
| Deferred | Low (1.9) | 0.11% | — | Freedesktop PopplerAI | 9/29/2026 | 9/30/2026 | A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name:… | |
| Deferred | High (7.8) | 0.09% | — | Seclore Filesecure Desktop ClientAI | 9/25/2026 | 9/30/2026 | Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems. | |
| Awaiting Analysis | High (7.5) | 0.79% | — | Gnome Remote DesktopAI | 9/23/2026 | 9/24/2026 | A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an… | |
| Deferred | High (7.4) | 0.16% | — | Mrpear DesktopsmsAI | 9/21/2026 | 9/24/2026 | DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can… | |
| Deferred | High (7.1) | 0.18% | — | Joplin DesktopAI | 9/21/2026 | 9/23/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.yml causes NsisUpdater.verifySignature() to skip comparison of a downloaded… | |
| Awaiting Analysis | High (8.3) | 0.20% | — | Telegram DesktopAI | 9/21/2026 | 9/22/2026 | Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group… | |
| Awaiting Analysis | Low (3.2) | 0.14% | — | Freedesktop Xdg-dbus-proxyAI | 9/18/2026 | 9/22/2026 | xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to… | |
| Deferred | Low (2.1) | 0.43% | — | Freedesktop PopplerAI | 9/18/2026 | 9/22/2026 | A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be… | |
| Deferred | Low (2.1) | 0.43% | — | Freedesktop PopplerAI | 9/18/2026 | 9/18/2026 | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is… | |
| Deferred | Low (2.1) | 0.59% | — | Freedesktop PopplerAI | 9/18/2026 | 9/22/2026 | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is… | |
| Deferred | Low (2.1) | 0.56% | — | Freedesktop PopplerAI | 9/18/2026 | 9/22/2026 | A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSample results in integer overflow. The attack may be performed from remote. The… | |
| Awaiting Analysis | Low (2.6) | 0.22% | — | Mattermost Desktop APPAI | 9/17/2026 | 9/18/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID:… | |
| Awaiting Analysis | Low (3.7) | 0.13% | — | Mattermost Desktop APPAI | 9/17/2026 | 9/18/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different connected server via the desktopAPI.leaveCall… | |
| Deferred | Medium (4.3) | 0.28% | — | Canva DesktopAI | 9/17/2026 | 9/18/2026 | Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session. | |
| Awaiting Analysis | Medium (4.7) | 0.15% | — | Mattermost Desktop APPAI | 9/16/2026 | 9/17/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this improvement under the Mattermost responsible disclosure policy. Mattermost Advisory… | |
| Awaiting Analysis | High (7.7) | 0.34% | — | Oracle WEB Applications Desktop IntegratorAIOracle E-business SuiteAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Web Applications… | |
| Awaiting Analysis | Medium (5.1) | 0.18% | — | Newell Brands Dymo Connect DesktopAI | 9/15/2026 | 9/22/2026 | The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension… | |
| Awaiting Analysis | Medium (6.5) | 0.34% | — | Oracle WEB Applications Desktop IntegratorAIOracle E-business SuiteAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications… | |
| Awaiting Analysis | Critical (9.4) | 0.20% | — | Apple MacosAIDocker DesktopAI | 9/15/2026 | 9/16/2026 | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host… | |
| Awaiting Analysis | High (7.8) | 0.17% | — | Parallels DesktopAI | 9/14/2026 | 9/18/2026 | Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon… | |
| Deferred | High (8.4) | 0.18% | — | Rakuten Kobo Desktop ApplicationAI | 9/14/2026 | 9/16/2026 | The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation. | |
| Deferred | High (8.6) | 0.19% | — | Autodesk Fusion DesktopAI | 9/10/2026 | 9/11/2026 | A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing… | |
| Analyzed | High (8.8) | 0.82% | — | Microsoft Remote Desktop Client | 9/8/2026 | 9/22/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analyzed | High (8.8) | 0.82% | — | Microsoft Remote Desktop Client | 9/8/2026 | 9/22/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |