Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.18% | — | Omnissa Workspace ONE Tunnel | 8/7/2026 | 10/7/2026 | Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Omnissa Workspace ONE AssistAI | 9/6/2026 | 23/7/2026 | Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability. | |
| Aplazada | Media (5.3) | 0.24% | — | Omnissa Workspace ONE UEMAI | 12/11/2025 | 17/6/2026 | Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks. | |
| Aplazada | Media (5.4) | 0.19% | — | Omnissa Workspace ONE UEMAI | 11/8/2025 | 17/6/2026 | Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system information, potentially enabling enumeration of internal network resources. | |
| Aplazada | Alta (7.5) | 22% | 💥 Exploit | Omnissa Workspace ONE UEMAI | 11/8/2025 | 17/6/2026 | Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints. | |
| Aplazada | Media (6.8) | 0.36% | — | Vmware Workspace ONE UEMAI | 27/6/2024 | 17/6/2026 | VMware Workspace One UEM update addresses an information exposure vulnerability. A malicious actor with network access to the Workspace One UEM may be able to perform an attack resulting in an information exposure. | |
| Modificada | Media (4.6) | 0.40% | — | Vmware Workspace ONE Launcher | 12/12/2023 | 17/6/2026 | Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information. | |
| Modificada | Media (6.1) | 0.40% | — | Vmware Workspace ONE UEM | 31/10/2023 | 17/6/2026 | VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and retrieve their SAML response to login as the victim user. | |
| Modificada | Media (6.1) | 0.35% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector | 30/5/2023 | 17/6/2026 | VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. | |
| Modificada | Media (6.8) | 0.92% | — | Vmware Workspace ONE Content | 28/2/2023 | 17/6/2026 | VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode. | |
| Modificada | Crítica (9.8) | 0.88% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token. | |
| Modificada | Media (6.1) | 0.46% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window. | |
| Modificada | Crítica (9.8) | 0.88% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Crítica (9.8) | 0.99% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Crítica (9.8) | 1.0% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Alta (7.8) | 2.4% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Vrealize Suite Lifecycle Manager | 20/5/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | |
| Modificada | Crítica (9.8) | 56% | 💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+1 | 20/5/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. | |
| Modificada | Media (5.3) | 0.85% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims. | |
| Analizada | Alta (7.8) | 36% | ⚠ Explotación activa💥 Exploit | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'. | |
| Modificada | Media (4.3) | 0.51% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI. | |
| Modificada | Alta (7.2) | 3.1% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution. | |
| Modificada | Alta (7.2) | 24% | 💥 Exploit | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution. | |
| Modificada | Crítica (9.8) | 50% | 💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework. | |
| Modificada | Crítica (9.8) | 7.8% | — | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+1 | 11/4/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. |