Skip to main content

Vendor/product archive

parallels / parallels_desktop CVEs

Beta · best-effort

74 CVEs tagged to parallels / parallels_desktop0 Critical, 47 High, 25 Medium, 2 Low, 0 Unrated.

CVE-2025-31359

Published Jun 3, 2025

A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54189

Published Jun 3, 2025

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken,…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52561

Published Jun 3, 2025

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is delete…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36486

Published Jun 3, 2025

A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6240

Published Jun 21, 2024

Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populat…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6154

Published Jun 20, 2024

Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected instal…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6153

Published Jun 20, 2024

Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local attackers to downgrade Parallels software on affected inst…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50228

Published May 3, 2024

Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50227

Published May 3, 2024

Parallels Desktop virtio-gpu Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50226

Published May 3, 2024

Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27328

Published May 3, 2024

Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27327

Published May 3, 2024

Parallels Desktop Toolgate Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected install…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27326

Published May 3, 2024

Parallels Desktop Toolgate Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27325

Published May 3, 2024

Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27324

Published May 3, 2024

Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27323

Published May 3, 2024

Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27322

Published May 3, 2024

Parallels Desktop Service Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34892

Published Jul 18, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34891

Published Jul 18, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34890

Published Jul 18, 2022

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the abilit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34889

Published Jul 18, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execut…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34987

Published Jul 15, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (49187). An attacker must first obtain the ability to execut…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34986

Published Jul 15, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An attacker must first obtain the ability to execut…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34864

Published Oct 25, 2021

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execut…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34857

Published Oct 25, 2021

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execut…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 74 CVEsPage 1 of 3