VDI vulnerabilities

Showing 1 - 50 of 148 CVEs

  1. CVE-2026-46716 Published Jun 12, 2026

    Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Command. At every tick of the scheduler, the dashboard pushes that command to every server in the global ServerShared map — including servers that belong to other tenants (admin's servers, other members' servers). Each agent runs the command and returns the output, which is then sent to the attacker's own NotificationGroup → attacker-controlled webhook. This issue has been patched in version 2.0.8.

  2. CVE-2026-45639 Published Jun 9, 2026

    Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

  3. CVE-2026-42913 Published Jun 9, 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  4. CVE-2026-42908 Published Jun 9, 2026

    Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

  5. CVE-2026-47280 Published May 22, 2026

    Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

  6. CVE-2026-41104 Published May 22, 2026

    Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

  7. CVE-2026-41090 Published May 22, 2026

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

  8. CVE-2026-40412 Published May 22, 2026

    Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

  9. CVE-2026-40411 Published May 22, 2026

    Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

  10. CVE-2026-33843 Published May 22, 2026

    Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

  11. CVE-2026-23652 Published May 22, 2026

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.

  12. CVE-2026-32253 Published May 22, 2026

    Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY, X509_V_ERR_CERT_NOT_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as success. This can allow an untrusted certificate to pass authentication and access protected HTTPS endpoints. This issue has been fixed in version 2026.516.143833.

  13. CVE-2026-30905 Published May 13, 2026

    External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.

  14. CVE-2026-6759 Published Apr 21, 2026

    Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

  15. CVE-2026-32157 Published Apr 14, 2026

    Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  16. CVE-2026-3055 Published Mar 23, 2026

    Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

  17. CVE-2026-4368 Published Mar 23, 2026

    Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup

  18. CVE-2026-22719 Published Feb 25, 2026

    VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

  19. CVE-2026-22769 Published Feb 17, 2026

    Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.

  20. CVE-2026-21533 Published Feb 10, 2026

    Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

  21. CVE-2026-21525 Published Feb 10, 2026

    Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

  22. CVE-2026-21519 Published Feb 10, 2026

    Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

  23. CVE-2026-21514 Published Feb 10, 2026

    Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

  24. CVE-2026-21513 Published Feb 10, 2026

    Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

  25. CVE-2026-21510 Published Feb 10, 2026

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

  26. CVE-2026-21982 Published Jan 20, 2026

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

  27. CVE-2026-21956 Published Jan 20, 2026

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

  28. CVE-2026-20805 Published Jan 13, 2026

    Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

  29. CVE-2025-64740 Published Nov 13, 2025

    Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

  30. CVE-2025-60703 Published Nov 11, 2025

    Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

  31. CVE-2025-59230 Published Oct 14, 2025

    Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

  32. CVE-2025-59202 Published Oct 14, 2025

    Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

  33. CVE-2025-58718 Published Oct 14, 2025

    Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  34. CVE-2025-6759 Published Jul 8, 2025

    Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS

  35. CVE-2025-48817 Published Jul 8, 2025

    Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  36. CVE-2025-6543 Published Jun 25, 2025

    Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

  37. CVE-2025-5777 Published Jun 17, 2025

    Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

  38. CVE-2025-5349 Published Jun 17, 2025

    Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway

  39. CVE-2025-21416 Published Apr 30, 2025

    Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.

  40. CVE-2025-27482 Published Apr 8, 2025

    Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

  41. CVE-2025-27480 Published Apr 8, 2025

    Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

  42. CVE-2025-24045 Published Mar 11, 2025

    Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

  43. CVE-2025-24035 Published Mar 11, 2025

    Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

  44. CVE-2025-22226 Published Mar 4, 2025

    VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

  45. CVE-2025-22225 Published Mar 4, 2025

    VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

  46. CVE-2025-22224 Published Mar 4, 2025

    VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

  47. CVE-2025-21297 Published Jan 14, 2025

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  48. CVE-2024-49115 Published Dec 12, 2024

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  49. CVE-2024-49106 Published Dec 12, 2024

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  50. CVE-2024-49105 Published Dec 12, 2024

    Remote Desktop Client Remote Code Execution Vulnerability