Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1256 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.19% | — | Vmware Tools | 27/10/2023 | 17/6/2026 | VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate privileges within the virtual machine. | |
| Modificada | Alta (7.5) | 1.1% | — | Vmware Rabbitmq Java Client | 25/10/2023 | 17/6/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from DoS… | |
| Modificada | Media (4.9) | 1.1% | — | Vmware Rabbitmq | 25/10/2023 | 17/6/2026 | RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target… | |
| Modificada | Media (4.3) | 0.67% | — | Vmware Vcenter Server | 25/10/2023 | 17/6/2026 | vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Vmware Vcenter Server | 25/10/2023 | 17/6/2026 | vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution. | |
| Modificada | Alta (7.8) | 0.16% | — | Vmware Fusion | 20/10/2023 | 17/6/2026 | VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious actor with local non-administrative user privileges may… | |
| Modificada | Alta (7) | 0.13% | — | Vmware Fusion | 20/10/2023 | 17/6/2026 | VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious actor with local non-administrative user… | |
| Modificada | Media (6) | 0.20% | — | Vmware WorkstationVmware Fusion | 20/10/2023 | 17/6/2026 | VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged… | |
| Modificada | Alta (7.8) | 0.20% | — | Vmware Aria Operations FOR Logs | 20/10/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass. | |
| Modificada | Crítica (9.8) | 45% | 💥 PoC | Vmware Aria Operations FOR Logs | 20/10/2023 | 17/6/2026 | VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. | |
| Modificada | Media (4.3) | 1.5% | 💥 PoC | Vmware Spring Advanced Message Queuing Protocol | 19/10/2023 | 17/6/2026 | In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provided, all classes could be deserialized.… | |
| Modificada | Media (6.7) | 0.19% | — | Vmware Aria OperationsVmware Cloud Foundation | 27/9/2023 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | |
| Modificada | Media (4.3) | 0.42% | — | Vmware Spring FOR Graphql | 20/9/2023 | 17/6/2026 | A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through… | |
| Modificada | Alta (7.5) | 1.5% | — | Vmware ToolsVmware Open VM ToolsFedoraproject FedoraDebian Linux+1 | 31/8/2023 | 17/6/2026 | A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest… | |
| Modificada | Crítica (9.8) | 67% | 💥 Exploit | Vmware Aria Operations FOR Networks | 29/8/2023 | 17/6/2026 | Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI. | |
| Modificada | Alta (7.2) | 20% | — | Vmware Aria Operations FOR Networks | 29/8/2023 | 17/6/2026 | Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution. | |
| Modificada | Alta (7.8) | 2.1% | 💥 PoC | Vmware Spring FOR Apache Kafka | 24/8/2023 | 17/6/2026 | In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an… | |
| Modificada | Media (5.5) | 0.13% | — | Dell Replay Manager FOR VmwareDell Storage Integration Tools FOR VmwareDell Storage Vsphere Client Plugin | 16/8/2023 | 17/6/2026 | Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to… | |
| Modificada | Media (5.3) | 0.49% | — | Vmware Horizon Client | 4/8/2023 | 17/6/2026 | VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relating to the internal network configuration. | |
| Modificada | Media (5.3) | 0.46% | — | Vmware Horizon Client | 4/8/2023 | 17/6/2026 | VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests. | |
| Modificada | Media (6.5) | 0.64% | — | Vmware Isolation SegmentVmware Tanzu Application Service FOR Virtual Machines | 26/7/2023 | 17/6/2026 | The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials… | |
| Modificada | Crítica (9.8) | 4.0% | 💥 PoC | Vmware Spring Security | 19/7/2023 | 17/6/2026 | Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass. | |
| Modificada | Media (5.3) | 0.66% | 💥 PoC | Vmware Spring Security | 18/7/2023 | 17/6/2026 | Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration if the application uses requestMatchers(String) and multiple servlets, one of them being Spring MVC’s DispatcherServlet. (DispatcherServlet is a Spring MVC component that… | |
| Modificada | Media (5.3) | 0.47% | — | Vmware Spring Hateoas | 17/7/2023 | 17/6/2026 | Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers if they are not behind a trusted proxy that ensures correctness of such headers, or if they don't have anything else in place to handle (and possibly discard) forwarded headers either… | |
| Modificada | Alta (7.5) | 0.63% | — | Vmware Sd-wan Edge Firmware | 6/7/2023 | 17/6/2026 | VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management. |