Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
–

117 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.79%—Gnome Remote DesktopAI23/9/202624/9/2026
A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an…
AnalizadaAlta (7.5)0.64%—Microsoft Remote Desktop Client8/9/202616/9/2026
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.82%—Microsoft Remote Desktop Client8/9/202622/9/2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft Remote Desktop Client8/9/202622/9/2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.86%—Microsoft Remote Desktop Client8/9/202622/9/2026
Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Pendiente de análisisMedia (4.3)0.15%—Devolutions Remote Desktop ManagerAIIronvncAI24/8/202628/8/2026
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Pendiente de análisisAlta (7.5)0.52%—Gnome Remote DesktopAIRedhat Enterprise LinuxAI31/7/202613/8/2026
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP…
AnalizadaAlta (7.5)0.66%—Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center17/7/202622/7/2026
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.2)0.50%—Devolutions Remote Desktop Manager26/6/202629/6/2026
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing…
AnalizadaMedia (5.5)0.15%—Devolutions Remote Desktop Manager16/6/202617/6/2026
Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.
ModificadaAlta (8.8)0.44%—Devolutions Remote Desktop Manager16/6/202620/7/2026
Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action. This…
AnalizadaAlta (7.5)1.0%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+119/6/202623/7/2026
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
ModificadaAlta (7.5)0.61%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+119/6/202623/7/2026
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.5)0.61%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+119/6/202623/7/2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
ModificadaAlta (8.8)0.82%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+119/6/202623/7/2026
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
ModificadaAlta (7.5)0.47%—Microsoft Remote Desktop ClientMicrosoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+39/6/202623/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
ModificadaAlta (7.5)0.47%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+119/6/202623/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft Remote Desktop ClientMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1114/4/202625/9/2026
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
ModificadaCrítica (9.8)0.50%—Devolutions Remote Desktop Manager3/3/202617/6/2026
Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information to other users, by creating or editing…
AplazadaAlta (8.4)0.36%—Remote Desktop AuditAI3/2/202617/6/2026
Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wizard file import process. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) bypass and execute shellcode when importing computer…
AnalizadaBaja (3.3)0.20%—Devolutions Remote Desktop Manager8/1/202617/6/2026
Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0 on Windows allows an external observer to view a password on screen via a defective masking feature, for example during physical observation or screen sharing.
AnalizadaMedia (6.5)0.39%—Devolutions ServerDevolutions Remote Desktop Manager28/11/202517/6/2026
Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.
AnalizadaAlta (8.8)0.60%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+1414/10/202517/6/2026
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)1.0%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+138/7/202517/6/2026
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.5)1.4%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+1310/6/202517/6/2026
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.