Product
parallels desktop
151 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-31359
CVE-2024-54189
CVE-2024-52561
CVE-2024-36486
CVE-2025-0413
CVE-2024-6240
CVE-2024-6154
CVE-2024-6153
CVE-2023-50228
CVE-2023-50227
CVE-2023-50226
CVE-2023-27328
CVE-2023-27327
CVE-2023-27326
CVE-2023-27325
CVE-2023-27324
CVE-2023-27323
CVE-2023-27322
CVE-2023-45894
CVE-2022-40870
CVE-2022-34902
CVE-2022-34901
CVE-2022-34900
CVE-2022-34899
CVE-2022-34892
CVE-2022-34891
CVE-2022-34890
CVE-2022-34889
CVE-2021-34987
CVE-2021-34986
CVE-2022-30777
CVE-2021-34869
CVE-2021-34868
CVE-2021-34867
CVE-2020-8968
CVE-2021-34864
CVE-2021-34857
CVE-2021-34856
CVE-2021-34855
CVE-2021-34854
CVE-2021-31432
CVE-2021-31431
CVE-2021-31430
CVE-2021-31429
CVE-2021-31428
CVE-2021-31427
CVE-2021-31426
CVE-2021-31425
CVE-2021-31424
CVE-2021-31423
CVE-2021-31422
CVE-2021-31421
CVE-2021-31420
CVE-2021-31419
CVE-2021-31418
CVE-2021-31417
CVE-2021-27278
CVE-2021-27260
CVE-2021-27259
CVE-2021-27244
CVE-2021-27243
CVE-2021-27242
CVE-2020-35710
CVE-2020-17402
CVE-2020-17401
CVE-2020-17400
CVE-2020-17399
CVE-2020-17398
CVE-2020-17397
CVE-2020-17396
CVE-2020-17395
CVE-2020-17394
CVE-2020-17393
CVE-2020-17392
CVE-2020-17391
CVE-2020-17390
CVE-2020-15860
CVE-2020-8876
CVE-2020-8875
CVE-2020-8874
CVE-2020-8873
CVE-2020-8872
CVE-2020-8871
CVE-2020-7213
CVE-2019-17148
CVE-2019-18793
CVE-2017-9447
CVE-2013-4878
CVE-2013-0133
CVE-2013-0132
CVE-2012-5004
CVE-2012-1557
CVE-2011-4856
CVE-2011-4855
CVE-2011-4854
CVE-2011-4853
CVE-2011-4852
CVE-2011-4851
CVE-2011-4850
CVE-2011-4849
CVE-2011-4848
CVE-2011-4847
CVE-2011-4777
CVE-2011-4776
CVE-2011-4768
CVE-2011-4767
CVE-2011-4766
CVE-2011-4765
CVE-2011-4764
CVE-2011-4763
CVE-2011-4762
CVE-2011-4761
CVE-2011-4760
CVE-2011-4759
CVE-2011-4758
CVE-2011-4757
CVE-2011-4756
CVE-2011-4755
CVE-2011-4754
CVE-2011-4753
CVE-2011-4749
CVE-2011-4748
CVE-2011-4747
CVE-2011-4746
CVE-2011-4745
CVE-2011-4744
CVE-2011-4743
CVE-2011-4742
CVE-2011-4741
CVE-2011-4740
CVE-2011-4739
CVE-2011-4738
CVE-2011-4737
CVE-2011-4736
CVE-2011-4735
CVE-2011-4734
CVE-2011-4733
CVE-2011-4732
CVE-2011-4731
CVE-2011-4730
CVE-2011-4729
CVE-2011-4728
CVE-2011-4727
CVE-2011-4726
CVE-2011-4725
CVE-2008-6465
CVE-2007-4009
CVE-2007-2455
CVE-2007-2454
CVE-2007-1222
CVE-2006-5817
all versions
A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2
all versions
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740
all versions
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740
all versions
A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac
< 19.4.3.2-25228
Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows loca
< 19.3.0
Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker
< 18.1.0
Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local at
< 18.1.0
Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local attackers
< 19.1.0_\(54729\)
Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerab
< 19.1.0_\(54729\)
Parallels Desktop virtio-gpu Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers t
< 17.1.7_\(51588\)
Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to es
< 18.1.1_\(53328\)
Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to es
< 18.1.1_\(53328\)
Parallels Desktop Toolgate Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local att
< 18.1.1_\(53328\)
Parallels Desktop Toolgate Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers
< 18.1.0_\(53311\)
Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attack
< 18.1.0_\(53311\)
Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attack
< 18.1.0_\(53311\)
Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local atta
< 18.1.0_\(53311\)
Parallels Desktop Service Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attack
< 19.2.23975
The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which
all versions
The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability all
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39313) Agent
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 17.1.1 (51537). An
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (49187). An
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An
all versions
Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An a
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An a
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An a
>= 15.5 and <= 17.0
Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by upl
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.1.3
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An a
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An a
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.2-49151. An a
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.2-49151. An a
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An a
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-49141. An a
all versions
This vulnerability allows local attackers to delete arbitrary files on affected installations of Parallels Desktop 16.1.1-49141. A
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.0-48950. An a
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-49141. An a
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.0.1-
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-48919. An a
all versions
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.0.1-
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-48919. An a
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-48919. An a
all versions
Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the
< 16.0.0
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4
< 16.0.0
This vulnerability allows local attackers to disclose sensitive informations on affected installations of Parallels Desktop 15.1.4
< 16.0.0
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacke
< 16.0.0
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacke
< 16.0.0
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.4. An attack
< 16.0.0
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacke
< 16.0.0
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacke
< 16.0.0
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacke
< 16.0.0
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4.
< 15.1.4
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An
< 16.0.0
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.3-47255. An a
< 16.0.0
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An
< 15.1.4
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An a
all versions
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authentica
< 15.1.3
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.2-47123. An
< 15.1.3
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An a
< 15.1.3
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An a
< 15.1.3
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An a
< 15.1.3
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.1-
< 15.1.3
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.0-47107 . An
all versions
Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop
all versions
Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter.
all versions
In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validat
all versions
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper
all versions
Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Parallels Plesk Panel 11.0.9 allows local users to gai
all versions
The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remot
all versions
Multiple cross-site request forgery (CSRF) vulnerabilities in Parallels H-Sphere 3.3 Patch 1 allow remote attackers to hijack the
all versions
SQL injection vulnerability in admin/plib/api-rpc/Agent.php in Parallels Plesk Panel 7.x and 8.x before 8.6 MU#2, 9.x before 9.5 M
all versions
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, whi
all versions
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header's charset parameter for certain r
all versions
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corres
all versions
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes an RFC 1918 IP address within a web page, which allows
all versions
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates web pages containing external links in response to GE
all versions
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocompl
all versions
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not include the HTTPOnly flag in a Set-Cookie header for a
all versions
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set the secure flag for a cookie in an https session,
all versions
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a submitted password within an HTTP response body, whi
all versions
SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execu
all versions
Cross-site scripting (XSS) vulnerability in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Panel 10.4.4_build2011110
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allow re
all versions
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset p
all versions
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses
all versions
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allows remote attackers to obtain ASP sou
all versions
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a S
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business
all versions
Multiple SQL injection vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0
all versions
Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote a
all versions
Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might a
all versions
Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence abo
all versions
Parallels Plesk Small Business Panel 10.2.0 generates web pages containing external links in response to GET requests with query s
all versions
Parallels Plesk Small Business Panel 10.2.0 receives cleartext password input over HTTP, which allows remote attackers to obtain s
all versions
Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which make
all versions
Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it
all versions
Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document
all versions
Multiple cross-site scripting (XSS) vulnerabilities in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to injec
all versions
Multiple SQL injection vulnerabilities in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary
all versions
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autoc
all versions
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 has web pages containing e-mail addresses that are not inte
all versions
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not prevent the use of weak ciphers for SSL sessions,
all versions
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not disable the SSL 2.0 protocol, which makes it easie
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 allo
all versions
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 sends incorrect Content-Type headers for certain resources, wh
all versions
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 omits the Content-Type header's charset parameter for certain
all versions
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 has web pages containing e-mail addresses that are not intende
all versions
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a database connection string within a web page, which
all versions
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates web pages containing external links in response to G
all versions
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a password form field without disabling the autocomp
all versions
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 does not include the HTTPOnly flag in a Set-Cookie header for
all versions
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a submitted password within an HTTP response body, wh
all versions
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 receives cleartext password input over HTTP, which allows remo
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 allow r
all versions
Multiple SQL injection vulnerabilities in the Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 allow remote attacke
all versions
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 sends incorrect Content-Type headers for certai
all versions
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 omits the Content-Type header's charset paramet
all versions
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 includes an RFC 1918 IP address within a web pa
all versions
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabli
all versions
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not include the HTTPOnly flag in a Set-Coo
all versions
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not set the secure flag for a cookie in an
all versions
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build101111
all versions
Multiple SQL injection vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 allow
all versions
Multiple cross-site scripting (XSS) vulnerabilities in login.php in webshell4 in Parallels H-Sphere 3.0.0 P9 and 3.1 P1 allow remo
all versions
PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows rem
all versions
Parallels allows local users to cause a denial of service (virtual machine abort) via (1) certain INT instructions, as demonstrate
all versions
Heap-based buffer overflow in the VGA device in Parallels allows local users, with root access to the guest operating system, to t
all versions
Parallels Desktop for Mac before 20070216 implements Drag and Drop by sharing the entire host filesystem as the .psf share, which
all versions
prl_dhcpd in Parallels Desktop for Mac Build 1940 uses insecure permissions (0666) for /Library/Parallels/.dhcpd_configuration, wh