Vulnerabilities

Summary — last 7 days

New vulnerabilities3,047▲ 440 vs. last week
Critical / high1,452▲ 212 vs. last week
New active exploitation (KEV)8▼ 2 vs. last week
Unscored (no CVSS)365▲ 151 vs. last week
–

3,977 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredLow (1.9)0.11%—Freedesktop PopplerAI9/29/20269/30/2026
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading…
DeferredLow (1.9)0.11%—Freedesktop PopplerAI9/29/20269/30/2026
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name:…
DeferredHigh (7.8)0.09%—Seclore Filesecure Desktop ClientAI9/25/20269/30/2026
Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems.
Awaiting AnalysisHigh (7.5)0.79%—Gnome Remote DesktopAI9/23/20269/24/2026
A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an…
DeferredHigh (7.4)0.16%—Mrpear DesktopsmsAI9/21/20269/24/2026
DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can…
DeferredHigh (7.1)0.18%—Joplin DesktopAI9/21/20269/23/2026
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.yml causes NsisUpdater.verifySignature() to skip comparison of a downloaded…
Awaiting AnalysisHigh (8.3)0.20%—Telegram DesktopAI9/21/20269/22/2026
Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group…
Awaiting AnalysisLow (3.2)0.14%—Freedesktop Xdg-dbus-proxyAI9/18/20269/22/2026
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to…
DeferredLow (2.1)0.43%—Freedesktop PopplerAI9/18/20269/22/2026
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be…
DeferredLow (2.1)0.43%—Freedesktop PopplerAI9/18/20269/18/2026
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is…
DeferredLow (2.1)0.59%—Freedesktop PopplerAI9/18/20269/22/2026
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is…
DeferredLow (2.1)0.56%—Freedesktop PopplerAI9/18/20269/22/2026
A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSample results in integer overflow. The attack may be performed from remote. The…
Awaiting AnalysisLow (2.6)0.22%—Mattermost Desktop APPAI9/17/20269/18/2026
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID:…
Awaiting AnalysisLow (3.7)0.13%—Mattermost Desktop APPAI9/17/20269/18/2026
Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different connected server via the desktopAPI.leaveCall…
DeferredMedium (4.3)0.28%—Canva DesktopAI9/17/20269/18/2026
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
Awaiting AnalysisMedium (4.7)0.15%—Mattermost Desktop APPAI9/16/20269/17/2026
Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this improvement under the Mattermost responsible disclosure policy. Mattermost Advisory…
Awaiting AnalysisHigh (7.7)0.34%—Oracle WEB Applications Desktop IntegratorAIOracle E-business SuiteAI9/15/20269/16/2026
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Web Applications…
Awaiting AnalysisMedium (5.1)0.18%—Newell Brands Dymo Connect DesktopAI9/15/20269/22/2026
The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension…
Awaiting AnalysisMedium (6.5)0.34%—Oracle WEB Applications Desktop IntegratorAIOracle E-business SuiteAI9/15/20269/16/2026
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications…
Awaiting AnalysisCritical (9.4)0.20%—Apple MacosAIDocker DesktopAI9/15/20269/16/2026
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host…
Awaiting AnalysisHigh (7.8)0.17%—Parallels DesktopAI9/14/20269/18/2026
Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon…
DeferredHigh (8.4)0.18%—Rakuten Kobo Desktop ApplicationAI9/14/20269/16/2026
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.
DeferredHigh (8.6)0.19%—Autodesk Fusion DesktopAI9/10/20269/11/2026
A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing…
AnalyzedHigh (8.8)0.82%—Microsoft Remote Desktop Client9/8/20269/22/2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalyzedHigh (8.8)0.82%—Microsoft Remote Desktop Client9/8/20269/22/2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.