Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.40% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | |
| Analizada | Media (6.4) | 0.44% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | |
| Analizada | Alta (7.8) | 0.29% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to a root user on the appliance running VMware Aria Operations. | |
| Analizada | Alta (7.8) | 0.18% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations. | |
| Analizada | Crítica (9.8) | 17% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vcenter Server | 17/9/2024 | 17/6/2026 | The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet. | |
| Analizada | Crítica (9.8) | 55% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vcenter Server | 17/9/2024 | 17/6/2026 | The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | |
| Modificada | Alta (8.1) | 0.47% | — | Vmware Aria AutomationVmware Cloud Foundation | 11/7/2024 | 17/6/2026 | VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database. | |
| Analizada | Media (5.3) | 0.71% | — | Vmware Cloud FoundationVmware Vcenter Server | 25/6/2024 | 17/6/2026 | The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition. | |
| Analizada | Media (6.8) | 0.19% | — | Vmware Cloud FoundationVmware Esxi | 25/6/2024 | 17/6/2026 | VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host. | |
| Analizada | Alta (7.2) | 27% | ⚠ Explotación activa💥 PoC | Vmware Cloud FoundationVmware Esxi | 25/6/2024 | 17/6/2026 | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by… | |
| Analizada | Alta (7.8) | 5.0% | 💥 Exploit | Vmware Vcenter ServerVmware Cloud Foundation | 18/6/2024 | 17/6/2026 | The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance. | |
| Analizada | Crítica (9.8) | 22% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vcenter Server | 18/6/2024 | 17/6/2026 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | |
| Analizada | Media (4.9) | 0.99% | 💥 PoC | Vmware Cloud FoundationVmware Vcenter Server | 21/5/2024 | 17/6/2026 | The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data. | |
| Analizada | Alta (7.2) | 2.5% | 💥 PoC | Vmware Cloud FoundationVmware Vcenter Server | 21/5/2024 | 17/6/2026 | The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system. | |
| Modificada | Alta (7.8) | 0.17% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 21/5/2024 | 17/6/2026 | The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in… | |
| Analizada | Alta (7.1) | 2.3% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | |
| Analizada | Alta (8.2) | 0.50% | — | Vmware Cloud FoundationVmware Esxi | 5/3/2024 | 17/6/2026 | VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox. | |
| Analizada | Media (6.7) | 0.65% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained… | |
| Modificada | Media (6.7) | 0.19% | — | Vmware Aria OperationsVmware Cloud Foundation | 21/2/2024 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | |
| Modificada | Alta (8.3) | 0.95% | — | Vmware Aria AutomationVmware Cloud Foundation | 16/1/2024 | 17/6/2026 | Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows. | |
| Modificada | Media (6.7) | 0.19% | — | Vmware Aria OperationsVmware Cloud Foundation | 27/9/2023 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | |
| Modificada | Media (6.1) | 0.35% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector | 30/5/2023 | 17/6/2026 | VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. | |
| Modificada | Media (6.7) | 0.22% | — | Vmware Aria OperationsVmware Cloud Foundation | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | |
| Modificada | Media (6.7) | 0.18% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system. | |
| Modificada | Alta (7.2) | 1.0% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system. |