Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1256 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.52% | — | Vmware AccessVmware Cloud FoundationVmware Identity Manager Connector | 14/12/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3. | |
| Modificada | Alta (7.2) | 1.1% | — | Vmware AccessVmware Cloud FoundationVmware Identity Manager | 14/12/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2. | |
| Modificada | Baja (3.3) | 0.21% | — | Vmware Cloud FoundationVmware Esxi | 13/12/2022 | 17/6/2026 | VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure. | |
| Modificada | Media (5.3) | 48% | — | Vmware Cloud FoundationVmware Vcenter Server | 13/12/2022 | 17/6/2026 | The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header. | |
| Modificada | Media (5.5) | 0.13% | — | Vmware Vcenter ServerVmware Cloud Foundation | 13/12/2022 | 17/6/2026 | The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation. | |
| Modificada | Alta (8.8) | 0.32% | — | Vmware Cloud FoundationVmware Esxi | 13/12/2022 | 17/6/2026 | VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox. | |
| Modificada | Alta (7) | 0.26% | — | Vmware Open-vm-tools | 23/11/2022 | 16/6/2026 | An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter). | |
| Modificada | Media (6.7) | 0.28% | — | Vmware Open VM Tools | 23/11/2022 | 16/6/2026 | An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled. | |
| Modificada | Crítica (9.9) | 0.83% | — | Vmware Hyperic Agent | 12/11/2022 | 17/6/2026 | A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with the privileges of the Hyperic Agent process (often SYSTEM… | |
| Modificada | Crítica (9.8) | 0.81% | — | Vmware Hyperic Server | 12/11/2022 | 17/6/2026 | A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Modificada | Crítica (10) | 0.88% | — | Vmware Hyperic Server | 12/11/2022 | 17/6/2026 | A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the privileges of the Hyperic server process. NOTE: This… | |
| Modificada | Crítica (9.8) | 0.88% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token. | |
| Modificada | Media (6.1) | 0.46% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window. | |
| Modificada | Crítica (9.8) | 0.88% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Crítica (9.8) | 0.99% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Crítica (9.8) | 1.0% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 PoC | Vmware Bosh EditorVmware Cloudfoundry Manifest YML SupportVmware Concourse CI Pipeline EditorVmware Spring Boot Tools+1 | 4/11/2022 | 17/6/2026 | Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the… | |
| Modificada | Crítica (9.8) | 3.4% | 💥 PoC | Vmware Spring SecurityNetapp Active IQ Unified Manager | 31/10/2022 | 17/6/2026 | Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and… | |
| Modificada | Alta (8.1) | 1.1% | — | Vmware Spring SecurityNetapp Active IQ Unified Manager | 31/10/2022 | 17/6/2026 | Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by the Client (via the browser) to the Authorization Server which can lead to a… | |
| Modificada | Crítica (9.1) | 8.3% | 💥 Exploit | Vmware Cloud FoundationVmware NSX Data Center | 28/10/2022 | 17/6/2026 | VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure. | |
| Modificada | Media (4.9) | 0.64% | — | Vmware Vrealize Operations | 11/10/2022 | 17/6/2026 | VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with administrative privileges may be able to read arbitrary files containing sensitive data. | |
| Modificada | Media (6.5) | 0.21% | — | Vmware Cloud FoundationVmware Esxi | 7/10/2022 | 17/6/2026 | VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host. | |
| Modificada | Crítica (9.1) | 33% | — | Vmware Vcenter Server | 7/10/2022 | 17/6/2026 | The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server. | |
| Modificada | Alta (7.5) | 0.40% | — | Broadcom Rabbitmq ServerVmware Rabbitmq | 6/10/2022 | 17/6/2026 | RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and… | |
| Modificada | Baja (3.7) | 0.56% | — | Vmware Spring Data Rest | 21/9/2022 | 17/6/2026 | Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes. |