Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1256 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.7)0.52%—Vmware NSXAI9/10/202417/6/2026
VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.
AplazadaMedia (4.3)0.32%—Vmware NSXAI9/10/202417/6/2026
VMware NSX contains a content spoofing vulnerability. An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive information disclosure.
AplazadaCrítica (9.8)0.53%—Fydeos FOR PCAIFydeos FOR VmwareAIFydeos FOR YOUAIFydeos OpenfydeAI9/10/202417/6/2026
FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.
AnalizadaCrítica (9.8)17%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server17/9/202417/6/2026
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
AnalizadaCrítica (9.8)55%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server17/9/202417/6/2026
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
AplazadaAlta (7.5)15%💥 ExploitApache TomcatAIEclipse JettyAIVmware FrameworkAI13/9/202417/6/2026
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.…
AplazadaAlta (8.5)0.85%—Vmware VspcAI7/9/202417/6/2026
A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST API, leading to remote code execution on VSPC server.
AplazadaCrítica (9.9)1.2%—Vmware VspcAI7/9/202417/6/2026
A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.
AplazadaAlta (8.5)0.85%—Vmware VspcAI7/9/202417/6/2026
A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC server.
AplazadaCrítica (9.9)0.85%—Vmware VspcAI7/9/202417/6/2026
An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.
AnalizadaAlta (7.8)0.28%—Vmware Fusion3/9/202417/6/2026
VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion application.
AplazadaMedia (6.3)0.12%—Vmware Spring Boot LoaderAIVmware Spring Boot Loader ClassicAI23/8/202417/6/2026
Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.
AnalizadaMedia (4.3)0.57%—Vmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Oncommand Insight20/8/202417/6/2026
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true:
AnalizadaAlta (7.5)0.46%—Vmware Spring Security20/8/202417/6/2026
Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.
ModificadaAlta (8.8)35%💥 PoCVmware Spring Cloud Data Flow25/7/202417/6/2026
In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
AplazadaBaja (3.9)0.13%—Vmware UAAAI18/7/202417/6/2026
Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can allow them to perform operations beyond their intended permissions.
AplazadaCrítica (9)0.26%—Zowe ApimlAIVmware Cloud GatewayAI17/7/202417/6/2026
A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a user to the endpoints requiring an internal client certificate without any credentials. It could lead to managing components in there and allow an…
ModificadaAlta (8.1)0.47%—Vmware Aria AutomationVmware Cloud Foundation11/7/202417/6/2026
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
AplazadaAlta (8.2)0.36%—Vmware Cloud FunctionAI9/7/202417/6/2026
In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions. Specifically, an application is vulnerable when all of the following are true: User is using Spring Cloud Function Web…
ModificadaMedia (5.4)0.33%—Vmware Cloud Director4/7/202417/6/2026
VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks.
AplazadaMedia (5.3)0.20%—Vmware Cloud Director Object Storage ExtensionAI27/6/202417/6/2026
VMware Cloud Director Object Storage Extension contains an Insertion of Sensitive Information vulnerability. A malicious actor with adjacent access to web/proxy server logging may be able to obtain sensitive information from URLs that are logged.
AplazadaMedia (4.9)0.37%—Vmware Cloud DirectorAI27/6/202417/6/2026
VMware Cloud Director contains an Improper Privilege Management vulnerability. An authenticated tenant administrator for a given organization within VMware Cloud Director may be able to accidentally disable their organization leading to a Denial of Service for active sessions within their own organization's scope.
AplazadaMedia (6.8)0.36%—Vmware Workspace ONE UEMAI27/6/202417/6/2026
VMware Workspace One UEM update addresses an information exposure vulnerability. A malicious actor with network access to the Workspace One UEM may be able to perform an attack resulting in an information exposure.
AnalizadaMedia (5.3)0.71%—Vmware Cloud FoundationVmware Vcenter Server25/6/202417/6/2026
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
AnalizadaMedia (6.8)0.19%—Vmware Cloud FoundationVmware Esxi25/6/202417/6/2026
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.
Orbitaley — Vulnerabilidades