Skip to main content

Vendor archive

parallels CVEs

Beta · best-effort

154 CVEs tagged to vendor parallels20 Critical, 67 High, 65 Medium, 2 Low, 0 Unrated.

CVE-2025-31359

Published Jun 3, 2025

A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54189

Published Jun 3, 2025

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken,…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52561

Published Jun 3, 2025

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is delete…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36486

Published Jun 3, 2025

A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6240

Published Jun 21, 2024

Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populat…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6154

Published Jun 20, 2024

Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected instal…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6153

Published Jun 20, 2024

Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local attackers to downgrade Parallels software on affected inst…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50228

Published May 3, 2024

Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50227

Published May 3, 2024

Parallels Desktop virtio-gpu Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50226

Published May 3, 2024

Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27328

Published May 3, 2024

Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27327

Published May 3, 2024

Parallels Desktop Toolgate Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected install…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27326

Published May 3, 2024

Parallels Desktop Toolgate Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27325

Published May 3, 2024

Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27324

Published May 3, 2024

Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27323

Published May 3, 2024

Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27322

Published May 3, 2024

Parallels Desktop Service Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45894

Published Dec 14, 2023

The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code e…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40870

Published Nov 23, 2022

The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34902

Published Jul 18, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to ex…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34901

Published Jul 18, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to ex…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34900

Published Jul 18, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39313) Agent. An attacker must first obtain the ability to ex…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34899

Published Jul 18, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to ex…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34892

Published Jul 18, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 154 CVEsPage 1 of 7