Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1256 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 1.0% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/3/2025 | 4/8/2026 | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. | |
| Analizada | Alta (8.2) | 1.6% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform+1 | 4/3/2025 | 17/6/2026 | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. | |
| Analizada | Media (6.5) | 0.56% | — | Vmware Aria OperationsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known. | |
| Analizada | Media (4.8) | 0.40% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration. | |
| Analizada | Media (5.4) | 0.33% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user. | |
| Analizada | Crítica (9) | 0.67% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user. | |
| Analizada | Alta (7.7) | 0.68% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs | |
| Aplazada | Alta (8.6) | 0.66% | — | Vmware AVI Load BalancerAI | 28/1/2025 | 17/6/2026 | Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products. A malicious user with network access may be able to use specially crafted SQL queries to gain database access. | |
| Aplazada | Media (4.3) | 0.26% | — | Vmware Aria AutomationAI | 8/1/2025 | 17/6/2026 | VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network. | |
| Aplazada | Alta (7.5) | 56% | 💥 Exploit | Vmware Webmvc.fnAIVmware Webflux.fnAI | 19/12/2024 | 17/6/2026 | Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running. | |
| Aplazada | Baja (3.7) | 0.37% | — | Vmware LdapAI | 4/12/2024 | 17/6/2026 | A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0. The usage of String.toLowerCase() and String.toUpperCase() has some… | |
| Analizada | Media (4.8) | 0.31% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | |
| Analizada | Media (5.4) | 0.40% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | |
| Analizada | Media (6.4) | 0.44% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | |
| Analizada | Alta (7.8) | 0.29% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to a root user on the appliance running VMware Aria Operations. | |
| Analizada | Alta (7.8) | 0.18% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations. | |
| Aplazada | Media (5.3) | 0.72% | 💥 PoC | Vmware Spring MVCAI | 18/11/2024 | 17/6/2026 | Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack. | |
| Aplazada | Alta (8.7) | 3.4% | 💥 Exploit | Vmware Spring BootAI | 14/11/2024 | 17/6/2026 | common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or… | |
| Aplazada | Alta (8.5) | 0.44% | — | RancherAIVmware VsphereAI | 13/11/2024 | 17/6/2026 | A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy clusters through the vSphere cloud provider. This issue leads to the vSphere CPI and CSI passwords being stored in a plaintext object inside… | |
| Aplazada | Media (6.5) | 0.36% | — | RabbitmqAIVmware Tanzu RabbitmqAI | 6/11/2024 | 17/6/2026 | RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target virtual host & 3. HTTP API access. could… | |
| Analizada | Baja (3.3) | 0.14% | — | Hashicorp Vagrant Vmware Utility | 29/10/2024 | 17/6/2026 | The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes. This vulnerability, CVE-2024-10228, was fixed in Vagrant VMWare Utility 1.0.23 | |
| Aplazada | Crítica (9.1) | 1.7% | 💥 PoC | Vmware SecurityAIVmware WebfluxAI | 28/10/2024 | 17/6/2026 | Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must be true: | |
| Modificada | Media (5.3) | 0.62% | 💥 PoC | Vmware Spring Framework | 18/10/2024 | 17/6/2026 | The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected. | |
| Analizada | Alta (8.8) | 15% | — | Vmware HCX | 16/10/2024 | 17/6/2026 | An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX manager. Updates are available to remediate this… | |
| Aplazada | Media (6.7) | 0.29% | — | Vmware NSXAI | 9/10/2024 | 17/6/2026 | VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned. |