Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1256 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.19% | — | QOS Logback-coreAIJaninoAIVmware Spring FrameworkAI | 1/10/2025 | 25/6/2026 | ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution. A… | |
| Aplazada | Alta (7.5) | 0.69% | — | Vmware NSXAIVmware Nsx-tAIVmware Cloud FoundationAI | 29/9/2025 | 17/6/2026 | Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially leading to unauthorized access attempts. Impact: Username enumeration → facilitates unauthorized access. Attack Vector: Remote, unauthenticated. Severity:… | |
| Aplazada | Alta (8.1) | 0.80% | — | Vmware NSXAIVmware Nsx-tAIVmware Cloud FoundationAI | 29/9/2025 | 17/6/2026 | VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks. Impact: Username enumeration → credential brute force risk. Attack Vector: Remote, unauthenticated. Severity: Important.… | |
| Aplazada | Alta (8.5) | 0.64% | — | Vmware VcenterAI | 29/9/2025 | 17/6/2026 | VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks. | |
| Aplazada | Media (4.9) | 0.61% | — | Vmware Aria OperationsAI | 29/9/2025 | 17/6/2026 | VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations. | |
| Analizada | Alta (7.8) | 8.4% | ⚠ Explotación activa💥 PoC | Vmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+4 | 29/9/2025 | 17/6/2026 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the… | |
| Aplazada | Alta (7.6) | 0.28% | — | Vmware ToolsAIVmware VcenterAIVmware ESXAI | 29/9/2025 | 17/6/2026 | VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation… | |
| Aplazada | Crítica (10) | 3.5% | 💥 Exploit | Vmware Cloud GatewayAIVmware BootAIVmware WebfluxAI | 16/9/2025 | 17/6/2026 | Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: | |
| Aplazada | Alta (7.5) | 0.46% | — | Vmware FrameworkAIVmware SecurityAI | 16/9/2025 | 17/6/2026 | The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using… | |
| Aplazada | Alta (7.5) | 0.43% | — | Vmware Spring SecurityAI | 16/9/2025 | 17/6/2026 | The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your… | |
| Aplazada | Media (6.6) | 0.11% | — | Zoom Workplace VDI PluginAIVmware HorizonAI | 9/9/2025 | 17/6/2026 | Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective tracks) may allow an authenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (6.9) | 0.11% | — | Tomtretbar Vmware Vsan | 28/8/2025 | 25/9/2026 | Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept traffic. | |
| Aplazada | Media (5.9) | 2.1% | 💥 Exploit | Apache TomcatAIEclipse JettyAIVmware FrameworkAI | 18/8/2025 | 17/6/2026 | Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when all the following are true: We have verified that applications deployed on Apache Tomcat or Eclipse Jetty are not vulnerable, as long as… | |
| Aplazada | Alta (7.5) | 0.36% | — | Kubernetes Image BuilderAINutanixAIVmwareAI | 17/8/2025 | 17/6/2026 | A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when using the Nutanix or VMware OVA providers. These credentials, which allow root access, are disabled at the conclusion of the build. Kubernetes clusters are only affected if… | |
| Aplazada | Media (5.5) | 0.37% | — | Zlt2000 Microservices-platformAIVmware Spring BootAI | 8/8/2025 | 17/6/2026 | A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /actuator of the component Spring Actuator Interface. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Media (4.4) | 0.29% | — | Vmware VcenterAI | 29/7/2025 | 17/6/2026 | VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition. | |
| Aplazada | Media (6.1) | 0.38% | — | Vmware Reactor NettyAI | 16/7/2025 | 17/6/2026 | In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. | |
| Aplazada | Alta (7.1) | 3.0% | — | Vmware EsxiAIVmware WorkstationAIVmware FusionAIVmware ToolsAI | 15/7/2025 | 17/6/2026 | VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with… | |
| Aplazada | Crítica (9.3) | 0.46% | — | Vmware EsxiAIVmware WorkstationAIVmware FusionAI | 15/7/2025 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process… | |
| Aplazada | Crítica (9.3) | 0.46% | — | Vmware EsxiAIVmware WorkstationAIVmware FusionAI | 15/7/2025 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on… | |
| Aplazada | Crítica (9.3) | 2.6% | — | Vmware EsxiAIVmware WorkstationAIVmware FusionAI | 15/7/2025 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are… | |
| Aplazada | Media (5.3) | 0.34% | — | ZipkinAIVmware Spring Boot ActuatorAI | 4/7/2025 | 17/6/2026 | Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927. | |
| Aplazada | Alta (8.7) | 0.30% | — | HPE Oneview FOR Vmware VcenterAI | 26/6/2025 | 17/6/2026 | A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions). | |
| Aplazada | Media (6.5) | 0.60% | — | Vmware Spring FrameworkAI | 12/6/2025 | 17/6/2026 | Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input. Specifically, an… | |
| Aplazada | Media (6.8) | 0.33% | — | Vmware AVI Load BalancerAI | 12/6/2025 | 17/6/2026 | Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of the issue to be in the Moderate severity range https://www.broadcom.com/support/vmware-services/security-response with a maximum CVSSv3 base score of 6.8… |