Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1256 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.90%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and…
ModificadaCrítica (9.8)1.4%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
ModificadaCrítica (9.8)34%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
ModificadaCrítica (9.8)1.2%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.
ModificadaCrítica (9.8)1.8%—Vmware Vcenter Server22/6/202317/6/2026
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts…
AnalizadaBaja (3.9)14%⚠ Explotación activaVmware ToolsDebian LinuxFedoraproject Fedora13/6/202317/6/2026
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
ModificadaAlta (7.5)79%💥 ExploitVmware Vrealize Network Insight7/6/202317/6/2026
Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.
ModificadaAlta (8.8)82%💥 ExploitVmware Vrealize Network Insight7/6/202317/6/2026
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution.
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitVmware Aria Operations FOR Networks7/6/202317/6/2026
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
ModificadaMedia (5.5)0.23%—Vmware Tools7/6/202317/6/2026
VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service condition…
ModificadaMedia (6.1)0.35%—Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector30/5/202317/6/2026
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
ModificadaMedia (6.1)0.47%—Broadcom Vmware Nsx-t Data Center26/5/202317/6/2026
NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages.
ModificadaAlta (7.5)0.91%—Vmware Spring Boot26/5/202317/6/2026
In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.
ModificadaCrítica (9.1)0.75%—Vmware Greenplum Database15/5/202317/6/2026
Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file writes. An attacker can use this vulnerability to overwrite…
ModificadaMedia (6.7)0.22%—Vmware Aria OperationsVmware Cloud Foundation12/5/202317/6/2026
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
ModificadaMedia (6.7)0.18%—Vmware Cloud FoundationVmware Vrealize Operations12/5/202317/6/2026
VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system.
ModificadaAlta (7.2)1.0%—Vmware Cloud FoundationVmware Vrealize Operations12/5/202317/6/2026
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.
ModificadaAlta (8.8)0.65%—Vmware Cloud FoundationVmware Vrealize Operations12/5/202317/6/2026
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
ModificadaMedia (6)0.37%—Vmware FusionVmware Workstation25/4/202317/6/2026
VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
ModificadaAlta (8.2)2.0%—Vmware FusionVmware Workstation25/4/202317/6/2026
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
ModificadaAlta (8.8)0.87%💥 PoCVmware FusionVmware Workstation25/4/202317/6/2026
VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
ModificadaAlta (7.8)0.38%—Vmware Fusion25/4/202317/6/2026
VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.
AnalizadaAlta (7.5)64%⚠ Explotación activaNetapp Smi-s ProviderSuse Manager ServerSuse Linux Enterprise ServerVmware Esxi+125/4/202317/6/2026
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
ModificadaCrítica (9.8)1.1%—Vmware Spring Boot20/4/202317/6/2026
In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to…
ModificadaAlta (7.2)1.6%—Vmware Aria Operations FOR LogsVmware Cloud Foundation20/4/202317/6/2026
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.
Orbitaley — Vulnerabilidades