Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1256 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.19%—Vmware Tools27/10/202317/6/2026
VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate privileges within the virtual machine.
ModificadaAlta (7.5)1.1%—Vmware Rabbitmq Java Client25/10/202317/6/2026
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from DoS…
ModificadaMedia (4.9)1.1%—Vmware Rabbitmq25/10/202317/6/2026
RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target…
ModificadaMedia (4.3)0.67%—Vmware Vcenter Server25/10/202317/6/2026
vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitVmware Vcenter Server25/10/202317/6/2026
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
ModificadaAlta (7.8)0.16%—Vmware Fusion20/10/202317/6/2026
VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious actor with local non-administrative user privileges may…
ModificadaAlta (7)0.13%—Vmware Fusion20/10/202317/6/2026
VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious actor with local non-administrative user…
ModificadaMedia (6)0.20%—Vmware WorkstationVmware Fusion20/10/202317/6/2026
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged…
ModificadaAlta (7.8)0.20%—Vmware Aria Operations FOR Logs20/10/202317/6/2026
VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.
ModificadaCrítica (9.8)45%💥 PoCVmware Aria Operations FOR Logs20/10/202317/6/2026
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
ModificadaMedia (4.3)1.5%💥 PoCVmware Spring Advanced Message Queuing Protocol19/10/202317/6/2026
In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provided, all classes could be deserialized.…
ModificadaMedia (6.7)0.19%—Vmware Aria OperationsVmware Cloud Foundation27/9/202317/6/2026
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
ModificadaMedia (4.3)0.42%—Vmware Spring FOR Graphql20/9/202317/6/2026
A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through…
ModificadaAlta (7.5)1.5%—Vmware ToolsVmware Open VM ToolsFedoraproject FedoraDebian Linux+131/8/202317/6/2026
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest…
ModificadaCrítica (9.8)67%💥 ExploitVmware Aria Operations FOR Networks29/8/202317/6/2026
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.
ModificadaAlta (7.2)20%—Vmware Aria Operations FOR Networks29/8/202317/6/2026
Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution.
ModificadaAlta (7.8)2.1%💥 PoCVmware Spring FOR Apache Kafka24/8/202317/6/2026
In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an…
ModificadaMedia (5.5)0.13%—Dell Replay Manager FOR VmwareDell Storage Integration Tools FOR VmwareDell Storage Vsphere Client Plugin16/8/202317/6/2026
Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to…
ModificadaMedia (5.3)0.49%—Vmware Horizon Client4/8/202317/6/2026
VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relating to the internal network configuration.
ModificadaMedia (5.3)0.46%—Vmware Horizon Client4/8/202317/6/2026
VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests.
ModificadaMedia (6.5)0.64%—Vmware Isolation SegmentVmware Tanzu Application Service FOR Virtual Machines26/7/202317/6/2026
The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials…
ModificadaCrítica (9.8)4.0%💥 PoCVmware Spring Security19/7/202317/6/2026
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
ModificadaMedia (5.3)0.66%💥 PoCVmware Spring Security18/7/202317/6/2026
Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration if the application uses requestMatchers(String) and multiple servlets, one of them being Spring MVC’s DispatcherServlet. (DispatcherServlet is a Spring MVC component that…
ModificadaMedia (5.3)0.47%—Vmware Spring Hateoas17/7/202317/6/2026
Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers if they are not behind a trusted proxy that ensures correctness of such headers, or if they don't have anything else in place to handle (and possibly discard) forwarded headers either…
ModificadaAlta (7.5)0.63%—Vmware Sd-wan Edge Firmware6/7/202317/6/2026
VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management.