Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.10% | — | Remote Control FOR Zoom Contact CenterZoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 16/7/2026 | 17/8/2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. | |
| Aplazada | Alta (8.5) | 0.17% | — | Matrix42 Remote Control HostAI | 19/6/2026 | 29/9/2026 | Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory with a crafted… | |
| Analizada | Alta (7.8) | 0.11% | — | Zoom Remote Control | 12/6/2026 | 29/6/2026 | Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access. | |
| Pendiente de análisis | Media (4) | 0.15% | — | HCL Bigfix Remote Control ServerAI | 27/5/2026 | 17/6/2026 | A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources. | |
| Aplazada | Alta (8.4) | 0.43% | — | Netop Remote Control ClientAI | 13/8/2025 | 16/6/2026 | NetOp (now part of Impero Software) Remote Control Client v9.5 is vulnerable to a stack-based buffer overflow when processing .dws configuration files. If a .dws file contains a string longer than 520 bytes, the application fails to perform proper bounds checking, allowing an attacker to execute arbitrary code when… | |
| Aplazada | Alta (8.2) | 0.20% | — | HCL Bigfix Remote Control ServerAI | 29/7/2025 | 17/6/2026 | Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages. | |
| Aplazada | Crítica (9.3) | 2.3% | — | DG Remote Control ServerAI | 23/7/2025 | 17/6/2026 | Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the default configuration. The server exposes a custom UDP-based control protocol that accepts remote keyboard input events without verification. An attacker on the same… | |
| Aplazada | Alta (7.8) | 0.23% | — | Solarwinds Dameware Mini Remote ControlAI | 2/6/2025 | 17/6/2026 | The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to be susceptible to this vulnerability. | |
| Modificada | Alta (7.8) | 0.22% | — | Hitachi IT Operations DirectorHitachi JOB Management Partner 1/it Desktop Management-managerHitachi JOB Management Partner 1/it Desktop Management 2-managerHitachi JOB Management Partner 1/remote Control Agent+10 | 12/10/2021 | 17/6/2026 | Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system. | |
| Modificada | Crítica (9.8) | 2.5% | — | Hitachi IT Operations DirectorHitachi JOB Management Partner 1/it Desktop Management-managerHitachi JOB Management Partner 1/it Desktop Management 2-managerHitachi JOB Management Partner 1/remote Control Agent+10 | 12/10/2021 | 17/6/2026 | Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS. | |
| Modificada | Crítica (9.1) | 4.0% | — | Solarwinds Dameware Mini Remote Control | 13/7/2021 | 17/6/2026 | In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM. | |
| Modificada | Crítica (9.8) | 3.8% | — | Ivanti Desktop&server ManagementIvanti Service Manager Heat Remote Control | 6/8/2020 | 17/6/2026 | Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet. | |
| Modificada | Crítica (9.8) | 5.1% | — | Solarwinds Dameware Mini Remote Control | 8/10/2019 | 17/6/2026 | The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System… | |
| Modificada | Alta (7.4) | 26% | — | Solarwinds Dameware Mini Remote Control | 7/6/2019 | 17/6/2026 | Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information. | |
| Modificada | Alta (7.5) | 19% | — | Solarwinds Dameware Mini Remote Control | 2/5/2019 | 17/6/2026 | DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name. | |
| Modificada | Alta (7.5) | 0.84% | — | Abus Secvest Wireless Alarm System Fuaa50000 FirmwareAbus Secvest Wireless Remote Control Fube50014 FirmwareAbus Secvest Wireless Remote Control Fube50015 Firmware | 27/3/2019 | 17/6/2026 | Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote control (FUBE50014 or FUBE50015) relative to its controlled Secvest wireless alarm system FUAA50000 3.01.01, so that sent commands by the remote control are not accepted anymore. | |
| Modificada | Crítica (9.8) | 2.1% | — | Abus Secvest Wireless Alarm System Fuaa50000 FirmwareAbus Secvest Wireless Remote Control Fube50014 FirmwareAbus Secvest Wireless Remote Control Fube50015 Firmware | 27/3/2019 | 17/6/2026 | Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controls FUBE50014 and FUBE50015, an attacker is able to predict valid future rolling codes, and can thus remotely control the alarm system in an unauthorized way. | |
| Modificada | Media (6.5) | 0.64% | — | Abus Secvest Wireless Alarm System Fuaa50000 FirmwareAbus Secvest Wireless Remote Control Fube50014 FirmwareAbus Secvest Wireless Remote Control Fube50015 Firmware | 27/3/2019 | 17/6/2026 | An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, an attacker is able to eavesdrop sensitive data as cleartext (for instance, the current rolling code state). | |
| Modificada | Alta (7.8) | 1.7% | — | Solarwinds Dameware Mini Remote Control | 7/9/2018 | 17/6/2026 | SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow. | |
| Modificada | Alta (8.8) | 2.4% | — | IBM Endpoint Manager FOR Remote ControlIBM Tivoli Remote Control | 27/4/2018 | 16/6/2026 | IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309. | |
| Modificada | Media (4.8) | 0.32% | — | IBM Bigfix Remote Control | 29/3/2018 | 17/6/2026 | IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197. | |
| Modificada | Alta (8.8) | 1.9% | — | IBM Endpoint Manager FOR Remote Control | 29/3/2018 | 17/6/2026 | The on-demand plugin in IBM Endpoint Manager for Remote Control 9.0.1 and 9.1.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. IBM X-Force ID: 105196. | |
| Modificada | Media (5.9) | 0.66% | — | IBM Bigfix Remote Control | 27/3/2018 | 17/6/2026 | IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attackers to conduct spoofing attacks via unspecified vectors. IBM X-Force ID: 105200. | |
| Modificada | Media (6.7) | 0.31% | — | IBM Bigfix Remote Control | 31/1/2018 | 17/6/2026 | IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to be executed with Local System or root privileges. IBM X-Force ID: 123912. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM Bigfix Remote Control | 3/5/2017 | 17/6/2026 | IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without authentication. IBM X-Force ID: 5512. |