Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1256 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)27%⚠ Explotación activa💥 PoCVmware Cloud FoundationVmware Esxi25/6/202417/6/2026
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by…
AplazadaMedia (4.4)0.14%—Hitachi Storage Provider FOR Vmware VcenterAI25/6/202417/6/2026
Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.
AplazadaAlta (8.8)18%💥 PoCVmware Cloud Data FlowAIVmware SkipperAI19/6/202417/6/2026
Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted…
AnalizadaAlta (7.8)5.0%💥 ExploitVmware Vcenter ServerVmware Cloud Foundation18/6/202417/6/2026
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
ModificadaCrítica (9.8)12%—Vmware Vcenter Server18/6/202417/6/2026
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
AnalizadaCrítica (9.8)22%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server18/6/202417/6/2026
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
AnalizadaMedia (4.9)0.99%💥 PoCVmware Cloud FoundationVmware Vcenter Server21/5/202417/6/2026
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
AnalizadaAlta (7.2)2.5%💥 PoCVmware Cloud FoundationVmware Vcenter Server21/5/202417/6/2026
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
ModificadaAlta (7.8)0.17%—Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion21/5/202417/6/2026
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in…
AnalizadaMedia (6)0.51%—Vmware WorkstationVmware Fusion14/5/202417/6/2026
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
AnalizadaMedia (6)0.51%—Vmware WorkstationVmware Fusion14/5/202417/6/2026
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
ModificadaMedia (6.5)0.50%—Vmware WorkstationVmware Fusion14/5/202417/6/2026
VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition.
ModificadaAlta (8.2)0.68%—Vmware FusionVmware Workstation14/5/202417/6/2026
VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
AplazadaMedia (6.5)0.40%—Vmware AVI Load BalancerAI8/5/202417/6/2026
VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor with access to the system logs can view cloud connection credentials in plaintext.
AplazadaAlta (7.2)0.55%—Vmware AVI Load BalancerAI8/5/202417/6/2026
VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious actor with admin privileges on VMware Avi Load Balancer can create, modify, execute and delete files as a root user on the host system.
AplazadaAlta (8.1)1.2%💥 PoCVmware FrameworkAI16/4/202417/6/2026
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing…
AplazadaAlta (7.1)0.39%—Vmware Sd-wan OrchestratorAI2/4/202417/6/2026
VMware SD-WAN Orchestrator contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
AplazadaMedia (4.8)0.21%—Vmware Sd-wan EdgeAI2/4/202417/6/2026
VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the…
AplazadaAlta (7.4)0.41%—Vmware Sd-wan EdgeAI2/4/202417/6/2026
VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router UI during activation may be able to perform a command injection attack that could lead to full control of the router.
AplazadaMedia (6.1)0.53%—Vmware Authorization ServerAI20/3/202417/6/2026
Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not…
AplazadaAlta (8.2)0.96%—Vmware Spring SecurityAI18/3/202430/6/2026
In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication…
AnalizadaAlta (8.1)2.6%—Vmware Spring FrameworkNetapp Active IQ Unified Manager16/3/202417/6/2026
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is…
ModificadaMedia (4.3)0.41%—Vmware Cloud Director7/3/202417/6/2026
VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the instance.
AnalizadaAlta (7.1)2.3%—Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion5/3/202417/6/2026
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
AnalizadaAlta (8.2)0.50%—Vmware Cloud FoundationVmware Esxi5/3/202417/6/2026
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
Orbitaley — Vulnerabilidades