Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.40%—Vmware Aria OperationsVmware Cloud Foundation26/11/202417/6/2026
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
AnalizadaMedia (6.4)0.44%—Vmware Aria OperationsVmware Cloud Foundation26/11/202417/6/2026
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
AnalizadaAlta (7.8)0.29%—Vmware Aria OperationsVmware Cloud Foundation26/11/202417/6/2026
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to a root user on the appliance running VMware Aria Operations.
AnalizadaAlta (7.8)0.18%—Vmware Aria OperationsVmware Cloud Foundation26/11/202417/6/2026
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations.
AnalizadaCrítica (9.8)17%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server17/9/202417/6/2026
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
AnalizadaCrítica (9.8)55%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server17/9/202417/6/2026
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
ModificadaAlta (8.1)0.47%—Vmware Aria AutomationVmware Cloud Foundation11/7/202417/6/2026
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
AnalizadaMedia (5.3)0.71%—Vmware Cloud FoundationVmware Vcenter Server25/6/202417/6/2026
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
AnalizadaMedia (6.8)0.19%—Vmware Cloud FoundationVmware Esxi25/6/202417/6/2026
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.
AnalizadaAlta (7.2)27%⚠ Explotación activa💥 PoCVmware Cloud FoundationVmware Esxi25/6/202417/6/2026
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by…
AnalizadaAlta (7.8)5.0%💥 ExploitVmware Vcenter ServerVmware Cloud Foundation18/6/202417/6/2026
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
AnalizadaCrítica (9.8)22%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server18/6/202417/6/2026
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
AnalizadaMedia (4.9)0.99%💥 PoCVmware Cloud FoundationVmware Vcenter Server21/5/202417/6/2026
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
AnalizadaAlta (7.2)2.5%💥 PoCVmware Cloud FoundationVmware Vcenter Server21/5/202417/6/2026
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
ModificadaAlta (7.8)0.17%—Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion21/5/202417/6/2026
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in…
AnalizadaAlta (7.1)2.3%—Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion5/3/202417/6/2026
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
AnalizadaAlta (8.2)0.50%—Vmware Cloud FoundationVmware Esxi5/3/202417/6/2026
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
AnalizadaMedia (6.7)0.65%—Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion5/3/202417/6/2026
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained…
ModificadaMedia (6.7)0.19%—Vmware Aria OperationsVmware Cloud Foundation21/2/202417/6/2026
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
ModificadaAlta (8.3)0.95%—Vmware Aria AutomationVmware Cloud Foundation16/1/202417/6/2026
Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.
ModificadaMedia (6.7)0.19%—Vmware Aria OperationsVmware Cloud Foundation27/9/202317/6/2026
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
ModificadaMedia (6.1)0.35%—Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector30/5/202317/6/2026
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
ModificadaMedia (6.7)0.22%—Vmware Aria OperationsVmware Cloud Foundation12/5/202317/6/2026
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
ModificadaMedia (6.7)0.18%—Vmware Cloud FoundationVmware Vrealize Operations12/5/202317/6/2026
VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system.
ModificadaAlta (7.2)1.0%—Vmware Cloud FoundationVmware Vrealize Operations12/5/202317/6/2026
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.
Orbitaley — Vulnerabilidades