Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 1.1% | 💥 PoC | Vmware WorkstationVmware EsxiVmware Fusion | 14/12/2022 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation… | |
| Modificada | Baja (3.3) | 0.21% | — | Vmware Cloud FoundationVmware Esxi | 13/12/2022 | 17/6/2026 | VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure. | |
| Modificada | Alta (8.8) | 0.32% | — | Vmware Cloud FoundationVmware Esxi | 13/12/2022 | 17/6/2026 | VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox. | |
| Modificada | Media (6.5) | 0.21% | — | Vmware Cloud FoundationVmware Esxi | 7/10/2022 | 17/6/2026 | VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host. | |
| Modificada | Media (6.5) | 0.78% | — | Debian LinuxFedoraproject FedoraAMD Athlon X4 750 FirmwareAMD Athlon X4 760k Firmware+122 | 14/7/2022 | 17/6/2026 | Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. | |
| Modificada | Media (6.5) | 5.0% | — | Intel Core I7-6500u FirmwareIntel Core I7-6510u FirmwareIntel Core I7-6560u FirmwareIntel Core I7-6567u Firmware+125 | 12/7/2022 | 17/6/2026 | Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain… | |
| Modificada | Media (5.5) | 5.8% | — | XENFedoraproject FedoraIntel SGX DcapIntel SGX PSW+3 | 15/6/2022 | 17/6/2026 | Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 6.5% | — | XENFedoraproject FedoraIntel SGX DcapIntel SGX PSW+3 | 15/6/2022 | 17/6/2026 | Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 6.2% | — | XENFedoraproject FedoraIntel SGX DcapIntel SGX PSW+3 | 15/6/2022 | 17/6/2026 | Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.5) | 2.3% | — | Vmware Cloud FoundationVmware Esxi | 16/2/2022 | 17/6/2026 | ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests. | |
| Modificada | Alta (7.5) | 1.1% | — | Vmware FusionVmware Esxi | 16/2/2022 | 17/6/2026 | VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files. | |
| Modificada | Alta (7.8) | 0.30% | — | Vmware Cloud FoundationVmware Esxi | 16/2/2022 | 17/6/2026 | VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user. | |
| Modificada | Media (6.7) | 0.57% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 16/2/2022 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. | |
| Modificada | Media (6.7) | 0.73% | — | Vmware Cloud FoundationVmware FusionVmware Workstation PlayerVmware Workstation PRO+1 | 16/2/2022 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. | |
| Modificada | Alta (7.8) | 4.7% | — | Vmware Cloud FoundationVmware WorkstationVmware FusionVmware Esxi | 4/1/2022 | 17/6/2026 | VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this… | |
| Modificada | Alta (8.4) | 0.28% | — | Vmware FusionVmware WorkstationVmware Vsphere Esxi | 15/9/2021 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrative access to a virtual machine with a virtual NVMe… | |
| Modificada | Alta (7.5) | 0.96% | — | Vmware Cloud FoundationVmware Esxi | 13/7/2021 | 17/6/2026 | OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bounds read in OpenSLP service resulting in a denial-of-service condition. | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Vmware Cloud FoundationVmware Esxi | 13/7/2021 | 17/6/2026 | SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request. | |
| Modificada | Alta (8.8) | 45% | 💥 PoC | Vmware Cloud FoundationVmware Esxi | 24/2/2021 | 17/6/2026 | OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service… | |
| Analizada | Media (6.5) | 0.38% | — | Vmware WorkstationVmware EsxiVmware Fusion | 21/12/2020 | 17/6/2026 | VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal… | |
| Modificada | Alta (7.8) | 0.39% | — | Vmware Cloud FoundationVmware Esxi | 20/11/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege-escalation vulnerability that exists in the way certain system calls are being managed. A malicious actor with privileges within the VMX process only, may escalate their privileges on the… | |
| Modificada | Alta (8.2) | 0.41% | — | Vmware FusionVmware Cloud FoundationVmware WorkstationVmware Esxi | 20/11/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may… | |
| Modificada | Media (5.3) | 1.1% | — | Vmware EsxiVmware Cloud FoundationVmware WorkstationVmware Fusion | 20/10/2020 | 17/6/2026 | In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability. A malicious actor with access to a virtual machine may be able to trigger a memory leak… | |
| Analizada | Crítica (9.8) | 83% | ⚠ Explotación activa💥 PoC | Vmware Cloud FoundationVmware Esxi | 20/10/2020 | 12/8/2026 | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP… | |
| Modificada | Alta (7.7) | 0.83% | — | Vmware EsxiVmware Cloud FoundationVmware WorkstationVmware Workstation Player+1 | 20/10/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a… |