Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Lenovo Accessories AND Display Manager FOR EnterpriseAI | 13/8/2026 | 24/8/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Lenovo Accessories AND Display Manager FOR EnterpriseAI | 10/6/2026 | 17/6/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Analizada | Alta (7) | 0.11% | — | Dell Display Manager | 15/1/2025 | 17/6/2026 | Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to code execution and possibly privilege escalation. | |
| Analizada | Media (6.3) | 0.10% | — | Dell Display Manager | 15/1/2025 | 17/6/2026 | Dell Display Manager, versions prior to 2.3.2.20, contain a race condition vulnerability. A local malicious user could potentially exploit this vulnerability during installation, leading to arbitrary folder or file deletion. | |
| Aplazada | Alta (7.8) | 0.16% | — | Lenovo Display Control CenterAILenovo Accessories AND Display ManagerAI | 16/8/2024 | 17/6/2026 | An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges to kernel. | |
| Aplazada | Alta (7.8) | 0.16% | — | Lenovo Display Control CenterAILenovo Accessories AND Display ManagerAI | 16/8/2024 | 17/6/2026 | An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges. | |
| Modificada | Media (6.6) | 0.21% | — | Dell Display Manager | 6/2/2024 | 17/6/2026 | Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability during installation leading to arbitrary folder or file deletion | |
| Modificada | Alta (7.8) | 0.16% | — | Dell Display Manager | 6/2/2024 | 17/6/2026 | Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Display Manager | 20/4/2023 | 17/6/2026 | Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation. A local low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code on the operating system with high privileges. | |
| Modificada | Alta (7.1) | 0.14% | — | Dell Display Manager | 6/4/2023 | 17/6/2026 | Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder deletion vulnerability during uninstallation A local low privilege attacker could potentially exploit this vulnerability, leading to the deletion of arbitrary files on the operating system with high privileges. | |
| Modificada | Media (6.4) | 0.23% | — | Gnome Display Manager | 28/12/2020 | 17/6/2026 | A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to… | |
| Modificada | Media (6.8) | 1.1% | — | Gnome Display Manager | 10/11/2020 | 17/6/2026 | gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a new privileged account. | |
| Modificada | Alta (7.8) | 1.1% | — | SIS XGI VGA Display Manager | 15/1/2020 | 17/6/2026 | Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.1090 allows local users to gain privileges via a crafted 0x96002404 IOCTL call. | |
| Modificada | Baja (2.4) | 0.53% | — | Gnome Display ManagerRedhat Enterprise LinuxDebian LinuxOpensuse Leap | 5/11/2019 | 17/6/2026 | gdm3 3.14.2 and possibly later has an information leak before screen lock | |
| Modificada | Media (6.4) | 0.50% | — | Gnome Display ManagerCanonical Ubuntu LinuxRedhat Enterprise Linux | 6/2/2019 | 17/6/2026 | A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in user's session. | |
| Modificada | Alta (7.8) | 0.53% | — | Gnome Display Manager | 14/8/2018 | 17/6/2026 | The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution. | |
| Modificada | Media (6.4) | 0.39% | — | Gnome Display Manager | 26/7/2018 | 17/6/2026 | A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen. | |
| Modificada | Alta (7.2) | 0.41% | — | Fedoraproject FedoraGnome Display Manager | 24/11/2015 | 17/6/2026 | GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key. | |
| Modificada | Alta (7.2) | 0.92% | — | SIS Windows VGA Display Manager | 16/9/2015 | 17/6/2026 | Silicon Integrated Systems WindowsXP Display Manager (aka VGA Driver Manager and VGA Display Manager) 6.14.10.3930 allows local users to gain privileges via a crafted (1) 0x96002400 or (2) 0x96002404 IOCTL call. | |
| Modificada | Alta (10) | 4.8% | — | Canonical Ltsp Display ManagerCanonical Ubuntu Linux | 21/5/2014 | 16/6/2026 | The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window. | |
| Modificada | Baja (2.1) | 0.37% | — | Gnome Display Manager | 29/4/2014 | 17/6/2026 | GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a denial of service (unable to login) by pressing the cancel button after entering a user name. | |
| Modificada | Media (4.3) | 2.4% | — | X Display Manager | 27/12/2013 | 16/6/2026 | X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of the crypt API function that can return NULL, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by attempting to log into an account whose password field… | |
| Modificada | Media (6.9) | 0.37% | — | Gnome Display Manager | 10/9/2013 | 16/6/2026 | GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/. | |
| Modificada | Baja (1.9) | 0.52% | — | Gnome Display Manager | 21/12/2012 | 16/6/2026 | vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog logs. | |
| Modificada | Media (5) | 3.5% | — | X.org X Display ManagerAIOracle SolarisAI | 10/8/2004 | 16/6/2026 | X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request. |