Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.65% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation. | |
| Modificada | Alta (7.2) | 1.6% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 20/4/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root. | |
| Modificada | Crítica (9.8) | 70% | 💥 Exploit | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 20/4/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root. | |
| Modificada | Media (5.3) | 0.52% | — | Vmware AccessVmware Cloud FoundationVmware Identity Manager Connector | 14/12/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3. | |
| Modificada | Alta (7.2) | 1.1% | — | Vmware AccessVmware Cloud FoundationVmware Identity Manager | 14/12/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2. | |
| Modificada | Baja (3.3) | 0.21% | — | Vmware Cloud FoundationVmware Esxi | 13/12/2022 | 17/6/2026 | VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure. | |
| Modificada | Media (5.3) | 48% | — | Vmware Cloud FoundationVmware Vcenter Server | 13/12/2022 | 17/6/2026 | The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header. | |
| Modificada | Media (5.5) | 0.13% | — | Vmware Vcenter ServerVmware Cloud Foundation | 13/12/2022 | 17/6/2026 | The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation. | |
| Modificada | Alta (8.8) | 0.32% | — | Vmware Cloud FoundationVmware Esxi | 13/12/2022 | 17/6/2026 | VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox. | |
| Modificada | Crítica (9.1) | 8.3% | 💥 Exploit | Vmware Cloud FoundationVmware NSX Data Center | 28/10/2022 | 17/6/2026 | VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure. | |
| Modificada | Media (6.5) | 0.21% | — | Vmware Cloud FoundationVmware Esxi | 7/10/2022 | 17/6/2026 | VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host. | |
| Modificada | Alta (7.5) | 1.0% | — | Vmware Cloud FoundationVmware Vcenter Server | 13/7/2022 | 17/6/2026 | The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service. | |
| Modificada | Alta (7.8) | 2.4% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Vrealize Suite Lifecycle Manager | 20/5/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | |
| Modificada | Crítica (9.8) | 56% | 💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+1 | 20/5/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. | |
| Modificada | Media (5.3) | 0.85% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims. | |
| Analizada | Alta (7.8) | 36% | ⚠ Explotación activa💥 Exploit | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'. | |
| Modificada | Media (4.3) | 0.51% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI. | |
| Modificada | Alta (7.2) | 3.1% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution. | |
| Modificada | Alta (7.2) | 24% | 💥 Exploit | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+1 | 11/4/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. | |
| Analizada | Media (6.5) | 13% | ⚠ Explotación activa💥 PoC | Vmware Cloud FoundationVmware Vcenter Server | 29/3/2022 | 17/6/2026 | The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information. | |
| Modificada | Alta (7.8) | 0.35% | — | Vmware Cloud FoundationVmware NSX Data Center | 16/2/2022 | 17/6/2026 | VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root. | |
| Modificada | Alta (7.5) | 2.3% | — | Vmware Cloud FoundationVmware Esxi | 16/2/2022 | 17/6/2026 | ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests. | |
| Modificada | Alta (7.8) | 0.30% | — | Vmware Cloud FoundationVmware Esxi | 16/2/2022 | 17/6/2026 | VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user. | |
| Modificada | Media (6.7) | 0.57% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 16/2/2022 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. |