Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.65%—Vmware Cloud FoundationVmware Vrealize Operations12/5/202317/6/2026
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
ModificadaAlta (7.2)1.6%—Vmware Aria Operations FOR LogsVmware Cloud Foundation20/4/202317/6/2026
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.
ModificadaCrítica (9.8)70%💥 ExploitVmware Aria Operations FOR LogsVmware Cloud Foundation20/4/202317/6/2026
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
ModificadaMedia (5.3)0.52%—Vmware AccessVmware Cloud FoundationVmware Identity Manager Connector14/12/202217/6/2026
VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.
ModificadaAlta (7.2)1.1%—Vmware AccessVmware Cloud FoundationVmware Identity Manager14/12/202217/6/2026
VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.
ModificadaBaja (3.3)0.21%—Vmware Cloud FoundationVmware Esxi13/12/202217/6/2026
VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure.
ModificadaMedia (5.3)48%—Vmware Cloud FoundationVmware Vcenter Server13/12/202217/6/2026
The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header.
ModificadaMedia (5.5)0.13%—Vmware Vcenter ServerVmware Cloud Foundation13/12/202217/6/2026
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
ModificadaAlta (8.8)0.32%—Vmware Cloud FoundationVmware Esxi13/12/202217/6/2026
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.
ModificadaCrítica (9.1)8.3%💥 ExploitVmware Cloud FoundationVmware NSX Data Center28/10/202217/6/2026
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
ModificadaMedia (6.5)0.21%—Vmware Cloud FoundationVmware Esxi7/10/202217/6/2026
VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.
ModificadaAlta (7.5)1.0%—Vmware Cloud FoundationVmware Vcenter Server13/7/202217/6/2026
The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
ModificadaAlta (7.8)2.4%—Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Vrealize Suite Lifecycle Manager20/5/202217/6/2026
VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
ModificadaCrítica (9.8)56%💥 ExploitVmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+120/5/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
ModificadaMedia (5.3)0.85%—Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+113/4/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims.
AnalizadaAlta (7.8)36%⚠ Explotación activa💥 ExploitVmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+113/4/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.
ModificadaMedia (4.3)0.51%—Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+113/4/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.
ModificadaAlta (7.2)3.1%—Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+113/4/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.
ModificadaAlta (7.2)24%💥 ExploitVmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+113/4/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+111/4/202217/6/2026
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
AnalizadaMedia (6.5)13%⚠ Explotación activa💥 PoCVmware Cloud FoundationVmware Vcenter Server29/3/202217/6/2026
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
ModificadaAlta (7.8)0.35%—Vmware Cloud FoundationVmware NSX Data Center16/2/202217/6/2026
VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root.
ModificadaAlta (7.5)2.3%—Vmware Cloud FoundationVmware Esxi16/2/202217/6/2026
ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests.
ModificadaAlta (7.8)0.30%—Vmware Cloud FoundationVmware Esxi16/2/202217/6/2026
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.
ModificadaMedia (6.7)0.57%—Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi16/2/202217/6/2026
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Orbitaley — Vulnerabilidades