Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 0.80% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 20/10/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a… | |
| Modificada | Media (5.3) | 2.1% | — | Vmware Cloud FoundationVmware Vcenter ServerVmware Esxi | 21/8/2020 | 17/6/2026 | VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3. | |
| Modificada | Media (5.5) | 0.35% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 25/6/2020 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (11.x before 11.0.2) contain a heap overflow vulnerability in the vmxnet3 virtual network adapter. A malicious actor with local access to a virtual machine with a vmxnet3 network adapter… | |
| Modificada | Baja (3.8) | 0.40% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 25/6/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionality. A malicious actor with non-administrative local access to a… | |
| Modificada | Alta (8.2) | 0.60% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 25/6/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xHCI). A malicious actor with local administrative privileges… | |
| Modificada | Alta (7.5) | 0.49% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 25/6/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a heap-overflow vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may… | |
| Modificada | Alta (7.5) | 0.38% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 25/6/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 controller (EHCI). A malicious actor with local access to a… | |
| Modificada | Media (5.5) | 0.56% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 25/6/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the XHCI USB controller. A malicious actor with local access to a virtual machine may be able to read… | |
| Modificada | Media (4.7) | 0.47% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 25/6/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the EHCI USB controller. A malicious actor with local access to a virtual machine may be able to read… | |
| Modificada | Media (5.5) | 0.55% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 25/6/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with local access to a virtual machine may be able to read… | |
| Modificada | Alta (8.2) | 0.60% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 24/6/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a use-after-free vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics… | |
| Modificada | Alta (7.8) | 0.52% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 24/6/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an off-by-one heap-overflow vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with… | |
| Modificada | Baja (3.3) | 0.32% | — | Vmware FusionVmware WorkstationVmware Esxi | 29/5/2020 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware Fusion (11.x before 11.1.0) contain a memory leak vulnerability in the VMCI module. A malicious actor with local non-administrative access to a virtual machine may be able to crash the… | |
| Modificada | Media (5.5) | 0.47% | — | Vmware FusionVmware WorkstationVmware Esxi | 29/5/2020 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x before 11.5.2) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with non-administrative… | |
| Modificada | Crítica (9.3) | 1.3% | — | Vmware Esxi | 29/4/2020 | 17/6/2026 | ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-202004103-SG do not properly neutralize script-related HTML when viewing virtual machines attributes. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.3. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Vmware Horizon DaasVmware EsxiRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+12 | 6/12/2019 | 17/6/2026 | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8. | |
| Modificada | Media (6.5) | 2.1% | — | Vmware FusionVmware WorkstationVmware Esxi | 28/10/2019 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with normal user privileges to create a… | |
| Modificada | Alta (8.8) | 0.30% | — | Vmware HorizonVmware Remote ConsoleVmware WorkstationVmware Fusion+1 | 10/10/2019 | 17/6/2026 | ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5. | |
| Modificada | Crítica (9.6) | 1.6% | — | Vmware FusionVmware WorkstationVmware Esxi | 20/9/2019 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain an out-of-bounds read vulnerability in the pixel shader functionality. Successful exploitation of this issue may lead to… | |
| Modificada | Media (5.4) | 0.97% | — | Vmware EsxiVmware Vsphere EsxiVmware Vcenter Server | 18/9/2019 | 17/6/2026 | VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session… | |
| Modificada | Media (5.3) | 1.7% | — | Vmware Esxi | 11/7/2019 | 17/6/2026 | VMware ESXi 6.5 suffers from partial denial of service vulnerability in hostd process. Patch ESXi650-201907201-UG for this issue is available. | |
| Modificada | Media (5.9) | 1.0% | — | Vmware FusionVmware WorkstationVmware Esxi | 15/4/2019 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds read vulnerability. Exploitation of this issue requires an attacker to have access to a virtual… | |
| Modificada | Media (6.8) | 1.1% | — | Vmware FusionVmware WorkstationVmware Esxi | 15/4/2019 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain multiple out-of-bounds read vulnerabilities in the shader translator. Exploitation of these issues requires an attacker to… | |
| Modificada | Media (6.8) | 1.7% | — | Vmware FusionVmware WorkstationVmware Esxi | 15/4/2019 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds vulnerability with the vertex shader functionality. Exploitation of this issue requires an… | |
| Modificada | Media (6.8) | 1.0% | — | Vmware FusionVmware WorkstationVmware Esxi | 1/4/2019 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain a Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller… |