Vmware
Vmware Vcenter Server: vulnerabilidades y CVE
Vmware Vcenter Server tiene 84 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 20 son críticas y 12 figuran en el catálogo de explotación activa de CISA.
CVE84
Últimos 12 meses2
Críticas20
Explotadas activamente12
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-59310 | Crítica (9.8) | 2.6% | ⚠ Explotación activa | 30 jul 2026 | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. |
| CVE-2024-37079 | Crítica (9.8) | 22% | ⚠ Explotación activa | 18 jun 2024 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted… |
| CVE-2024-38812 | Crítica (9.8) | 55% | ⚠ Explotación activa | 17 sept 2024 | The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially… |
| CVE-2024-38813 | Crítica (9.8) | 17% | ⚠ Explotación activa | 17 sept 2024 | The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted… |
| CVE-2022-22948 | Media (6.5) | 13% | ⚠ Explotación activa | 29 mar 2022 | The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to… |
| CVE-2023-34048 | Crítica (9.8) | 99% | ⚠ Explotación activa | 25 oct 2023 | vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading… |
| CVE-2021-21973 | Media (5.3) | 88% | ⚠ Explotación activa | 24 feb 2021 | The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this… |
| CVE-2021-22017 | Media (5.3) | 49% | ⚠ Explotación activa | 23 sept 2021 | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass… |
| CVE-2020-3952 | Crítica (9.8) | 90% | ⚠ Explotación activa | 10 abr 2020 | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls. |
| CVE-2021-21972 | Crítica (9.8) | 100% | ⚠ Explotación activa | 24 feb 2021 | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted… |
| CVE-2021-22005 | Crítica (9.8) | 100% | ⚠ Explotación activa | 23 sept 2021 | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server… |
| CVE-2021-21985 | Crítica (9.8) | 100% | ⚠ Explotación activa | 26 may 2021 | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-59310 | Crítica (9.8) | 2.6% | ⚠ Explotación activa | 30 jul 2026 | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. |
| CVE-2026-59309 | Crítica (9.8) | 0.61% | — | 30 jul 2026 | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized… |
| CVE-2025-41228 | Media (4.3) | 0.89% | — | 20 may 2025 | VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL… |
| CVE-2025-41226 | Media (6.8) | 0.24% | — | 20 may 2025 | VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or… |
| CVE-2025-41225 | Alta (8.8) | 0.26% | — | 20 may 2025 | The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the… |
| CVE-2024-38813 | Crítica (9.8) | 17% | ⚠ Explotación activa | 17 sept 2024 | The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted… |
| CVE-2024-38812 | Crítica (9.8) | 55% | ⚠ Explotación activa | 17 sept 2024 | The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially… |
| CVE-2024-37087 | Media (5.3) | 0.71% | — | 25 jun 2024 | The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition. |
| CVE-2024-37081 | Alta (7.8) | 5.0% | — | 18 jun 2024 | The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate… |
| CVE-2024-37080 | Crítica (9.8) | 12% | — | 18 jun 2024 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted… |
| CVE-2024-37079 | Crítica (9.8) | 22% | ⚠ Explotación activa | 18 jun 2024 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted… |
| CVE-2024-22275 | Media (4.9) | 0.99% | — | 21 may 2024 | The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing… |
| CVE-2024-22274 | Alta (7.2) | 2.5% | — | 21 may 2024 | The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the… |
| CVE-2023-34056 | Media (4.3) | 0.67% | — | 25 oct 2023 | vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data. |
| CVE-2023-34048 | Crítica (9.8) | 99% | ⚠ Explotación activa | 25 oct 2023 | vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading… |
| CVE-2023-20896 | Alta (7.5) | 0.91% | — | 22 jun 2023 | The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a… |
| CVE-2023-20895 | Crítica (9.8) | 1.4% | — | 22 jun 2023 | The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability… |
| CVE-2023-20894 | Crítica (9.8) | 34% | — | 22 jun 2023 | The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending… |
| CVE-2023-20893 | Crítica (9.8) | 1.2% | — | 22 jun 2023 | The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on… |
| CVE-2023-20892 | Crítica (9.8) | 1.8% | — | 22 jun 2023 | The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit… |
| CVE-2022-31698 | Media (5.3) | 48% | — | 13 dic 2022 | The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service… |
| CVE-2022-31697 | Media (5.5) | 0.13% | — | 13 dic 2022 | The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation… |
| CVE-2022-31680 | Crítica (9.1) | 33% | — | 7 oct 2022 | The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on… |
| CVE-2022-22982 | Alta (7.5) | 1.0% | — | 13 jul 2022 | The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter… |
| CVE-2022-22948 | Media (6.5) | 13% | ⚠ Explotación activa | 29 mar 2022 | The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to… |
| CVE-2021-22049 | Crítica (9.8) | 1.7% | — | 24 nov 2021 | The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit… |
| CVE-2021-21980 | Alta (7.5) | 4.7% | — | 24 nov 2021 | The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive… |
| CVE-2021-22048 | Alta (8.8) | 10% | — | 10 nov 2021 | The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit… |
| CVE-2021-22020 | Media (5.5) | 0.23% | — | 23 sept 2021 | The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server. |
| CVE-2021-22019 | Alta (7.5) | 1.6% | — | 23 sept 2021 | The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.