Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1256 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.9)0.26%—Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform4/6/202517/6/2026
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.
AnalizadaMedia (6.9)0.31%—Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform4/6/202517/6/2026
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.
AnalizadaAlta (7.5)0.34%—Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform4/6/202517/6/2026
VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
AplazadaAlta (8.6)0.34%—Vmware Cloud GatewayAI30/5/202517/6/2026
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.
AplazadaAlta (7.7)4.0%💥 ExploitJavaAIVmware Spring BootAI21/5/202517/6/2026
OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized access to sensitive…
AplazadaCrítica (9.1)0.62%—Vmware SecurityAI21/5/202517/6/2026
Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an authorization bypass. Your application may be affected by this if the following are true: You are not affected if:
AplazadaMedia (4.3)0.89%💥 ExploitVmware EsxiAIVmware Vcenter ServerAI20/5/202517/6/2026
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.
AplazadaMedia (5.5)0.16%—Vmware EsxiAIVmware WorkstationAIVmware FusionAI20/5/202517/6/2026
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition.
AplazadaMedia (6.8)0.24%—Vmware EsxiAIVmware Vcenter ServerAIVmware ToolsAI20/5/202517/6/2026
VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools…
AplazadaAlta (8.8)0.26%—Vmware Vcenter ServerAI20/5/202517/6/2026
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
AnalizadaAlta (7.3)0.17%—Vmware Cloud Foundation20/5/202517/6/2026
VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.
AplazadaAlta (7.5)0.43%—Vmware Cloud FoundationAI20/5/202517/6/2026
VMware Cloud Foundation contains an information disclosure vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to gain access to sensitive information.
AplazadaAlta (8.2)0.67%—Vmware Cloud FoundationAI20/5/202517/6/2026
VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to access certain internal services.
AplazadaBaja (3.1)0.42%—Vmware Spring FrameworkAI16/5/202517/6/2026
CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks. Affected Spring Products and Versions Mitigation Users of affected versions…
AnalizadaAlta (8.2)0.34%—Vmware Aria AutomationVmware Cloud FoundationVmware Telco Cloud Platform13/5/202517/6/2026
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.
AplazadaMedia (6.1)0.27%—Vmware ToolsAI12/5/202517/6/2026
VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.
AplazadaMedia (5.1)0.32%—Vmware Spring Cloud BaseAI6/5/202517/6/2026
A vulnerability was found in fp2952 spring-cloud-base up to 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa. It has been declared as problematic. Affected by this vulnerability is the function sendBack of the file…
AplazadaAlta (7.3)0.43%💥 PoCVmware SecurityAIVmware BootAI28/4/202517/6/2026
EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. Your application may be affected by this if all the following conditions are met: You are not affected if any of the following is true:
AplazadaMedia (5.3)0.31%—Vmware Cloud ConfigAIVmware VaultAI10/4/202517/6/2026
In this case the SessionManager persists the first token it retrieves and will continue to use that token even if client requests to the Spring Cloud Config Server include a X-CONFIG-TOKEN header with a different value. Affected Spring Products and Versions Spring Cloud Config: * 2.2.1.RELEASE - 4.2.1 Mitigation Users…
AplazadaAlta (7.8)0.15%—Vmware Aria OperationsAI1/4/202517/6/2026
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can escalate their privileges to root on the appliance running VMware Aria Operations.
AplazadaMedia (6.1)0.21%—RabbitmqAIVmware Tanzu RabbitmqAI25/3/202517/6/2026
RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that could modify virtual host name on disk and then make it unrecoverable (with other on disk file modifications) can lead to arbitrary JavaScript code execution in the browsers of management UI users. When…
AplazadaAlta (7.8)0.35%—Vmware Tools FOR WindowsAI25/3/202517/6/2026
VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious actor with non-administrative privileges on a guest VM may gain ability to perform certain high privilege operations within that VM.
AplazadaMedia (5.3)0.50%💥 PoCVmware Spring SecurityAI24/3/202517/6/2026
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method…
AplazadaAlta (7.4)0.60%—Vmware Spring SecurityAI20/3/202517/6/2026
BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.
AnalizadaMedia (6)1.8%⚠ Explotación activaVmware EsxiVmware Cloud FoundationVmware FusionVmware Telco Cloud Infrastructure+24/3/202517/6/2026
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.