Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 56% | 💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+1 | 20/5/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. | |
| Modificada | Crítica (9.8) | 6.7% | — | Microsoft Workspace-tools | 13/5/2022 | 17/6/2026 | The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch subcommand in a way that additional flags can… | |
| Modificada | Alta (7.8) | 2.1% | — | IBM Planning Analytics Workspace | 25/4/2022 | 17/6/2026 | IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066. | |
| Modificada | Alta (8) | 0.78% | — | IBM Planning Analytics Workspace | 25/4/2022 | 17/6/2026 | IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 214025. | |
| Modificada | Media (6.5) | 1.7% | 💥 PoC | D2L Brightspace | 19/4/2022 | 17/6/2026 | A bypass exists for Desire2Learn/D2L Brightspace’s “Disable Right Click” option in the quizzing feature, which allows a quiz-taker to access print and copy functionality via the browser’s right click menu even when “Disable Right Click” is enabled on the quiz. | |
| Modificada | Baja (3.3) | 0.21% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | Hard-coded credentials in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enable attackers with command line access to access the device’s Wi-Fi module. | |
| Modificada | Alta (7.1) | 0.47% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices. | |
| Modificada | Alta (7.5) | 0.62% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to recover user credentials of the administrative interface. | |
| Modificada | Alta (7.5) | 1.9% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A XPath injection vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows unauthenticated remote attackers to access sensitive information and escalate privileges. | |
| Modificada | Media (6.3) | 0.21% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enables attackers to extract and tamper with the devices network configuration. | |
| Modificada | Media (6.1) | 0.85% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to inject arbitrary web script or HTML into various locations. | |
| Modificada | Alta (7.2) | 1.2% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and A11 and earlier enables attackers in possession of cryptographic material to access the device as root. | |
| Modificada | Media (6.1) | 0.66% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious websites. | |
| Modificada | Alta (8.1) | 1.3% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate privileges. | |
| Modificada | Alta (8.8) | 1.5% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands. | |
| Modificada | Media (6.7) | 0.25% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with command line access to the underlying Linux system to escalate privileges to the root user. | |
| Modificada | Media (5.3) | 0.85% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims. | |
| Analizada | Alta (7.8) | 36% | ⚠ Explotación activa💥 Exploit | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'. | |
| Modificada | Media (4.3) | 0.51% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI. | |
| Modificada | Alta (7.2) | 3.1% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution. | |
| Modificada | Alta (7.2) | 24% | 💥 Exploit | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution. | |
| Modificada | Crítica (9.8) | 50% | 💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework. | |
| Modificada | Crítica (9.8) | 7.8% | — | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+1 | 11/4/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. | |
| Modificada | Media (5.4) | 0.46% | — | Vmware Workspace ONE Boxer | 2/3/2022 | 17/6/2026 | VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary script within a user's window. |