Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1256 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)70%💥 ExploitVmware Aria Operations FOR LogsVmware Cloud Foundation20/4/202317/6/2026
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
ModificadaMedia (6.3)0.65%—Vmware Spring SecurityNetapp Active IQ Unified Manager19/4/202317/6/2026
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the…
ModificadaMedia (6.5)0.66%—Vmware Spring Session13/4/202317/6/2026
In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.
ModificadaMedia (6.5)1.1%—Vmware Spring Framework13/4/202317/6/2026
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
ModificadaAlta (7.5)3.5%💥 PoCVmware Spring Framework27/3/202317/6/2026
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
ModificadaMedia (6.5)0.97%—Vmware Spring Framework23/3/202317/6/2026
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
ModificadaMedia (5.5)0.22%—Vmware Spring Cloud ConfigVmware Spring Cloud VaultVmware Spring Vault23/3/202317/6/2026
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
ModificadaMedia (5.5)0.20%—HP Oneview FOR Vmware Vcenter1/3/202317/6/2026
HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.
ModificadaMedia (6.8)0.92%—Vmware Workspace ONE Content28/2/202317/6/2026
VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode.
ModificadaAlta (7.2)17%—Vmware Carbon Black APP Control22/2/202317/6/2026
VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted input allowing access to the underlying server operating…
ModificadaAlta (8.8)1.3%—Vmware Vrealize AutomationVmware Vrealize Orchestrator22/2/202317/6/2026
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.
ModificadaMedia (5.5)0.18%—Vmware Ixgben16/2/202317/6/2026
Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.1 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.20%—Vmware Ixgben16/2/202317/6/2026
Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.13 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.4)0.29%—Vmware Workstation3/2/202317/6/2026
VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on which Workstation is installed.
ModificadaAlta (8.8)0.40%—Vmware Vrealize Operations1/2/202317/6/2026
VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.
ModificadaMedia (5.3)24%💥 ExploitVmware Vrealize LOG Insight26/1/202317/6/2026
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.
ModificadaAlta (7.5)1.5%—Vmware Vrealize LOG Insight26/1/202317/6/2026
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.
ModificadaCrítica (9.8)87%💥 ExploitVmware Vrealize LOG Insight26/1/202317/6/2026
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
ModificadaCrítica (9.8)81%💥 ExploitVmware Vrealize LOG Insight26/1/202317/6/2026
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.
ModificadaAlta (7.5)1.6%—Apache ShiroVmware Spring Boot14/1/202317/6/2026
When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot < 2.6 default to Ant style pattern matching.…
ModificadaMedia (4.9)0.82%—Vmware Vrealize Operations16/12/202217/6/2026
vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.
ModificadaAlta (7.2)0.99%—Vmware Vrealize Operations16/12/202217/6/2026
vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.
ModificadaAlta (8.2)1.1%💥 PoCVmware WorkstationVmware EsxiVmware Fusion14/12/202217/6/2026
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation…
ModificadaAlta (7.5)1.9%—Vmware Vrealize LOG Insight14/12/202217/6/2026
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
ModificadaCrítica (9.8)1.7%—Vmware Vrealize Network Insight14/12/202217/6/2026
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.
Orbitaley — Vulnerabilidades