Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1256 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.90% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and… | |
| Modificada | Crítica (9.8) | 1.4% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication. | |
| Modificada | Crítica (9.8) | 34% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption. | |
| Modificada | Crítica (9.8) | 1.2% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server. | |
| Modificada | Crítica (9.8) | 1.8% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts… | |
| Analizada | Baja (3.9) | 14% | ⚠ Explotación activa | Vmware ToolsDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. | |
| Modificada | Alta (7.5) | 79% | 💥 Exploit | Vmware Vrealize Network Insight | 7/6/2023 | 17/6/2026 | Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure. | |
| Modificada | Alta (8.8) | 82% | 💥 Exploit | Vmware Vrealize Network Insight | 7/6/2023 | 17/6/2026 | Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution. | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Vmware Aria Operations FOR Networks | 7/6/2023 | 17/6/2026 | Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution. | |
| Modificada | Media (5.5) | 0.23% | — | Vmware Tools | 7/6/2023 | 17/6/2026 | VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in the VM3DMP driver leading to a denial-of-service condition… | |
| Modificada | Media (6.1) | 0.35% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector | 30/5/2023 | 17/6/2026 | VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. | |
| Modificada | Media (6.1) | 0.47% | — | Broadcom Vmware Nsx-t Data Center | 26/5/2023 | 17/6/2026 | NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages. | |
| Modificada | Alta (7.5) | 0.91% | — | Vmware Spring Boot | 26/5/2023 | 17/6/2026 | In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache. | |
| Modificada | Crítica (9.1) | 0.75% | — | Vmware Greenplum Database | 15/5/2023 | 17/6/2026 | Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file writes. An attacker can use this vulnerability to overwrite… | |
| Modificada | Media (6.7) | 0.22% | — | Vmware Aria OperationsVmware Cloud Foundation | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | |
| Modificada | Media (6.7) | 0.18% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system. | |
| Modificada | Alta (7.2) | 1.0% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system. | |
| Modificada | Alta (8.8) | 0.65% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation. | |
| Modificada | Media (6) | 0.37% | — | Vmware FusionVmware Workstation | 25/4/2023 | 17/6/2026 | VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. | |
| Modificada | Alta (8.2) | 2.0% | — | Vmware FusionVmware Workstation | 25/4/2023 | 17/6/2026 | VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. | |
| Modificada | Alta (8.8) | 0.87% | 💥 PoC | Vmware FusionVmware Workstation | 25/4/2023 | 17/6/2026 | VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. | |
| Modificada | Alta (7.8) | 0.38% | — | Vmware Fusion | 25/4/2023 | 17/6/2026 | VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system. | |
| Analizada | Alta (7.5) | 64% | ⚠ Explotación activa | Netapp Smi-s ProviderSuse Manager ServerSuse Linux Enterprise ServerVmware Esxi+1 | 25/4/2023 | 17/6/2026 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor. | |
| Modificada | Crítica (9.8) | 1.1% | — | Vmware Spring Boot | 20/4/2023 | 17/6/2026 | In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to… | |
| Modificada | Alta (7.2) | 1.6% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 20/4/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root. |