Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1256 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7)0.19%—QOS Logback-coreAIJaninoAIVmware Spring FrameworkAI1/10/202525/6/2026
ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution. A…
AplazadaAlta (7.5)0.69%—Vmware NSXAIVmware Nsx-tAIVmware Cloud FoundationAI29/9/202517/6/2026
Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially leading to unauthorized access attempts. Impact: Username enumeration → facilitates unauthorized access. Attack Vector: Remote, unauthenticated. Severity:…
AplazadaAlta (8.1)0.80%—Vmware NSXAIVmware Nsx-tAIVmware Cloud FoundationAI29/9/202517/6/2026
VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks. Impact: Username enumeration → credential brute force risk. Attack Vector: Remote, unauthenticated. Severity: Important.…
AplazadaAlta (8.5)0.64%—Vmware VcenterAI29/9/202517/6/2026
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.
AplazadaMedia (4.9)0.61%—Vmware Aria OperationsAI29/9/202517/6/2026
VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations.
AnalizadaAlta (7.8)8.4%⚠ Explotación activa💥 PoCVmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+429/9/202517/6/2026
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the…
AplazadaAlta (7.6)0.28%—Vmware ToolsAIVmware VcenterAIVmware ESXAI29/9/202517/6/2026
VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation…
AplazadaCrítica (10)3.5%💥 ExploitVmware Cloud GatewayAIVmware BootAIVmware WebfluxAI16/9/202517/6/2026
Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true:
AplazadaAlta (7.5)0.46%—Vmware FrameworkAIVmware SecurityAI16/9/202517/6/2026
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using…
AplazadaAlta (7.5)0.43%—Vmware Spring SecurityAI16/9/202517/6/2026
The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your…
AplazadaMedia (6.6)0.11%—Zoom Workplace VDI PluginAIVmware HorizonAI9/9/202517/6/2026
Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective tracks) may allow an authenticated user to conduct a disclosure of information via network access.
AnalizadaMedia (6.9)0.11%—Tomtretbar Vmware Vsan28/8/202525/9/2026
Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept traffic.
AplazadaMedia (5.9)2.1%💥 ExploitApache TomcatAIEclipse JettyAIVmware FrameworkAI18/8/202517/6/2026
Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when all the following are true: We have verified that applications deployed on Apache Tomcat or Eclipse Jetty are not vulnerable, as long as…
AplazadaAlta (7.5)0.36%—Kubernetes Image BuilderAINutanixAIVmwareAI17/8/202517/6/2026
A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when using the Nutanix or VMware OVA providers. These credentials, which allow root access, are disabled at the conclusion of the build. Kubernetes clusters are only affected if…
AplazadaMedia (5.5)0.37%—Zlt2000 Microservices-platformAIVmware Spring BootAI8/8/202517/6/2026
A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /actuator of the component Spring Actuator Interface. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has…
AplazadaMedia (4.4)0.29%—Vmware VcenterAI29/7/202517/6/2026
VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.
AplazadaMedia (6.1)0.38%—Vmware Reactor NettyAI16/7/202517/6/2026
In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
AplazadaAlta (7.1)3.0%—Vmware EsxiAIVmware WorkstationAIVmware FusionAIVmware ToolsAI15/7/202517/6/2026
VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with…
AplazadaCrítica (9.3)0.46%—Vmware EsxiAIVmware WorkstationAIVmware FusionAI15/7/202517/6/2026
VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process…
AplazadaCrítica (9.3)0.46%—Vmware EsxiAIVmware WorkstationAIVmware FusionAI15/7/202517/6/2026
VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on…
AplazadaCrítica (9.3)2.6%—Vmware EsxiAIVmware WorkstationAIVmware FusionAI15/7/202517/6/2026
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are…
AplazadaMedia (5.3)0.34%—ZipkinAIVmware Spring Boot ActuatorAI4/7/202517/6/2026
Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.
AplazadaAlta (8.7)0.30%—HPE Oneview FOR Vmware VcenterAI26/6/202517/6/2026
A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions).
AplazadaMedia (6.5)0.60%—Vmware Spring FrameworkAI12/6/202517/6/2026
Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input. Specifically, an…
AplazadaMedia (6.8)0.33%—Vmware AVI Load BalancerAI12/6/202517/6/2026
Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of the issue to be in the Moderate severity range https://www.broadcom.com/support/vmware-services/security-response with a maximum CVSSv3 base score of 6.8…