vciy

CVEs we hold for Parallels

Records whose assigning authority named Parallels as the affected vendor. Newest identifiers first, capped at 200.

Announced together

One group of these records was published under a single advisory. Its page names that advisory, counts what the group offers, and says what it does not cover.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2026-90894Parallels Desktop local privilege escalation via appliance extract argument injectionParallels Desktop for Mac
CVE-2026-18263Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation VulnerabilityParallels RAS Client
CVE-2026-18262Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation VulnerabilityParallels RAS Client
CVE-2026-13121Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation VulnerabilityParallels RAS Client
CVE-2025-31359no title heldParallels Desktop for Mac
CVE-2025-30074no title heldParallels Desktop
CVE-2025-0413Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation VulnerabilityParallels Desktop
CVE-2024-6240Improper privilege management vulnerability in Parallels DesktopParallels Desktop
CVE-2024-6154Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation VulnerabilityParallels Desktop
CVE-2024-6153Parallels Desktop Updater Protection Mechanism Failure Software Downgrade VulnerabilityParallels Desktop
CVE-2024-54189no title heldParallels Desktop for Mac
CVE-2024-52561no title heldParallels Desktop for Mac
CVE-2024-36486no title heldParallels Desktop for Mac
CVE-2023-50228Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation VulnerabilityParallels Desktop
CVE-2023-50227Parallels Desktop virtio-gpu Out-Of-Bounds Write Remote Code Execution VulnerabilityParallels Desktop
CVE-2023-50226Parallels Desktop Updater Link Following Local Privilege Escalation VulnerabilityParallels Desktop
CVE-2023-27328Parallels Desktop Toolgate XML Injection Local Privilege Escalation VulnerabilityParallels Desktop
CVE-2023-27327Parallels Desktop Toolgate Time-Of-Check Time-Of-Use Local Privilege Escalation VulnerabilityParallels Desktop
CVE-2023-27326Parallels Desktop Toolgate Directory Traversal Local Privilege Escalation VulnerabilityParallels Desktop
CVE-2023-27325Parallels Desktop Updater Improper Initialization Local Privilege Escalation VulnerabilityParallels Desktop
CVE-2023-27324Parallels Desktop Updater Improper Initialization Local Privilege Escalation VulnerabilityParallels Desktop
CVE-2023-27323Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation VulnerabilityParallels Desktop
CVE-2023-27322Parallels Desktop Service Improper Initialization Local Privilege Escalation VulnerabilityParallels Desktop
CVE-2022-34902no title heldParallels Access
CVE-2022-34901no title heldParallels Access
CVE-2022-34900no title heldParallels Access
CVE-2022-34899no title heldParallels Access
CVE-2022-34892no title heldParallels Desktop
CVE-2022-34891no title heldParallels Desktop
CVE-2022-34890no title heldParallels Desktop
CVE-2022-34889no title heldParallels Desktop
CVE-2021-34987no title heldParallels Desktop
CVE-2021-34986no title heldParallels Desktop
CVE-2021-34869no title heldParallels Desktop
CVE-2021-34868no title heldParallels Desktop
CVE-2021-34867no title heldParallels Desktop
CVE-2021-34864no title heldParallels Desktop
CVE-2021-34857no title heldParallels Desktop
CVE-2021-34856no title heldParallels Desktop
CVE-2021-34855no title heldParallels Desktop
CVE-2021-34854no title heldParallels Desktop
CVE-2021-31432no title heldParallels Desktop
CVE-2021-31431no title heldParallels Desktop
CVE-2021-31430no title heldParallels Desktop
CVE-2021-31429no title heldParallels Desktop
CVE-2021-31428no title heldParallels Desktop
CVE-2021-31427no title heldParallels Desktop
CVE-2021-31426no title heldParallels Desktop
CVE-2021-31425no title heldParallels Desktop
CVE-2021-31424no title heldParallels Desktop
CVE-2021-31423no title heldParallels Desktop
CVE-2021-31422no title heldParallels Desktop
CVE-2021-31421no title heldParallels Desktop
CVE-2021-31420no title heldParallels Desktop
CVE-2021-31419no title heldParallels Desktop
CVE-2021-31418no title heldParallels Desktop
CVE-2021-31417no title heldParallels Desktop
CVE-2021-27278no title heldParallels Desktop
CVE-2021-27260no title heldParallels Desktop
CVE-2021-27259no title heldParallels Desktop
CVE-2021-27244no title heldParallels Desktop
CVE-2021-27243no title heldParallels Desktop
CVE-2021-27242no title heldParallels Desktop
CVE-2020-8968Parallels Remote Application Server credentials management errorsParallels Remote Application Server (Client)
CVE-2020-8876no title heldParallels Desktop
CVE-2020-8875no title heldParallels Desktop
CVE-2020-8874no title heldParallels Desktop
CVE-2020-8873no title heldParallels Desktop
CVE-2020-8872no title heldParallels Desktop
CVE-2020-8871no title heldParallels Desktop
CVE-2020-17402no title heldParallels Desktop
CVE-2020-17401no title heldParallels Desktop
CVE-2020-17400no title heldParallels Desktop
CVE-2020-17399no title heldParallels Desktop
CVE-2020-17398no title heldParallels Desktop
CVE-2020-17397no title heldParallels Desktop
CVE-2020-17396no title heldParallels Desktop
CVE-2020-17395no title heldParallels Desktop
CVE-2020-17394no title heldParallels Desktop
CVE-2020-17393no title heldParallels Desktop
CVE-2020-17392no title heldParallels Desktop
CVE-2020-17391no title heldParallels Desktop
CVE-2020-17390no title heldParallels Desktop
CVE-2019-17148no title heldParallels Desktop

84 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.