Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1256 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 27% | ⚠ Explotación activa💥 PoC | Vmware Cloud FoundationVmware Esxi | 25/6/2024 | 17/6/2026 | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by… | |
| Aplazada | Media (4.4) | 0.14% | — | Hitachi Storage Provider FOR Vmware VcenterAI | 25/6/2024 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4. | |
| Aplazada | Alta (8.8) | 18% | 💥 PoC | Vmware Cloud Data FlowAIVmware SkipperAI | 19/6/2024 | 17/6/2026 | Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted… | |
| Analizada | Alta (7.8) | 5.0% | 💥 Exploit | Vmware Vcenter ServerVmware Cloud Foundation | 18/6/2024 | 17/6/2026 | The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance. | |
| Modificada | Crítica (9.8) | 12% | — | Vmware Vcenter Server | 18/6/2024 | 17/6/2026 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | |
| Analizada | Crítica (9.8) | 22% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vcenter Server | 18/6/2024 | 17/6/2026 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | |
| Analizada | Media (4.9) | 0.99% | 💥 PoC | Vmware Cloud FoundationVmware Vcenter Server | 21/5/2024 | 17/6/2026 | The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data. | |
| Analizada | Alta (7.2) | 2.5% | 💥 PoC | Vmware Cloud FoundationVmware Vcenter Server | 21/5/2024 | 17/6/2026 | The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system. | |
| Modificada | Alta (7.8) | 0.17% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 21/5/2024 | 17/6/2026 | The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in… | |
| Analizada | Media (6) | 0.51% | — | Vmware WorkstationVmware Fusion | 14/5/2024 | 17/6/2026 | VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine. | |
| Analizada | Media (6) | 0.51% | — | Vmware WorkstationVmware Fusion | 14/5/2024 | 17/6/2026 | VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine. | |
| Modificada | Media (6.5) | 0.50% | — | Vmware WorkstationVmware Fusion | 14/5/2024 | 17/6/2026 | VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition. | |
| Modificada | Alta (8.2) | 0.68% | — | Vmware FusionVmware Workstation | 14/5/2024 | 17/6/2026 | VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. | |
| Aplazada | Media (6.5) | 0.40% | — | Vmware AVI Load BalancerAI | 8/5/2024 | 17/6/2026 | VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor with access to the system logs can view cloud connection credentials in plaintext. | |
| Aplazada | Alta (7.2) | 0.55% | — | Vmware AVI Load BalancerAI | 8/5/2024 | 17/6/2026 | VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious actor with admin privileges on VMware Avi Load Balancer can create, modify, execute and delete files as a root user on the host system. | |
| Aplazada | Alta (8.1) | 1.2% | 💥 PoC | Vmware FrameworkAI | 16/4/2024 | 17/6/2026 | Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing… | |
| Aplazada | Alta (7.1) | 0.39% | — | Vmware Sd-wan OrchestratorAI | 2/4/2024 | 17/6/2026 | VMware SD-WAN Orchestrator contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. | |
| Aplazada | Media (4.8) | 0.21% | — | Vmware Sd-wan EdgeAI | 2/4/2024 | 17/6/2026 | VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the… | |
| Aplazada | Alta (7.4) | 0.41% | — | Vmware Sd-wan EdgeAI | 2/4/2024 | 17/6/2026 | VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router UI during activation may be able to perform a command injection attack that could lead to full control of the router. | |
| Aplazada | Media (6.1) | 0.53% | — | Vmware Authorization ServerAI | 20/3/2024 | 17/6/2026 | Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not… | |
| Aplazada | Alta (8.2) | 0.96% | — | Vmware Spring SecurityAI | 18/3/2024 | 30/6/2026 | In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication… | |
| Analizada | Alta (8.1) | 2.6% | — | Vmware Spring FrameworkNetapp Active IQ Unified Manager | 16/3/2024 | 17/6/2026 | Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is… | |
| Modificada | Media (4.3) | 0.41% | — | Vmware Cloud Director | 7/3/2024 | 17/6/2026 | VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the instance. | |
| Analizada | Alta (7.1) | 2.3% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | |
| Analizada | Alta (8.2) | 0.50% | — | Vmware Cloud FoundationVmware Esxi | 5/3/2024 | 17/6/2026 | VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox. |