Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.79% | — | Vmware FusionVmware WorkstationVmware Esxi | 1/4/2019 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out-of-bounds read/write vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller… | |
| Modificada | Media (6.5) | 0.45% | — | Vmware WorkstationVmware FusionVmware Esxi | 4/12/2018 | 17/6/2026 | VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest. | |
| Modificada | Alta (8.8) | 1.3% | 💥 PoC | Vmware WorkstationVmware FusionVmware Esxi | 4/12/2018 | 17/6/2026 | VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below contain uninitialized stack memory usage in the vmxnet3 virtual network… | |
| Modificada | Alta (8.8) | 0.47% | — | Vmware WorkstationVmware FusionVmware Esxi | 16/10/2018 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds read vulnerability in SVGA device. This issue may allow a guest to execute code on the host. | |
| Modificada | Media (6.5) | 0.43% | — | Vmware EsxiVmware WorkstationVmware Fusion | 9/10/2018 | 17/6/2026 | VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some… | |
| Modificada | Media (6.5) | 3.0% | — | Vmware WorkstationVmware FusionVmware Esxi | 25/7/2018 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain a denial-of-service vulnerability due to NULL pointer dereference issue in RPC handler.… | |
| Modificada | Alta (8.1) | 2.2% | — | Vmware FusionVmware WorkstationVmware Esxi | 9/7/2018 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash… | |
| Modificada | Alta (8.1) | 2.2% | — | Vmware FusionVmware WorkstationVmware Esxi | 9/7/2018 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash… | |
| Modificada | Alta (8.1) | 2.9% | — | Vmware WorkstationVmware EsxiVmware Fusion | 9/7/2018 | 17/6/2026 | VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash… | |
| Modificada | Media (5.6) | 94% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Alta (8.8) | 3.2% | — | Vmware FusionVmware WorkstationVmware Esxi | 20/12/2017 | 17/6/2026 | VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a stack overflow via a specific set of VNC packets. Successful exploitation of this issue could result… | |
| Modificada | Media (6.1) | 0.91% | — | Vmware Esxi | 20/12/2017 | 17/6/2026 | The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability by injecting Javascript, which might get executed when… | |
| Modificada | Alta (8.8) | 3.6% | — | Vmware Workstation PROVmware EsxiVmware Fusion | 20/12/2017 | 17/6/2026 | VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a heap overflow via a specific set of VNC packets resulting in heap corruption. Successful exploitation of this issue could… | |
| Modificada | Alta (8.8) | 6.2% | — | BusyboxDebian LinuxVmware EsxiRedlion N-tron 702-w Firmware+2 | 20/11/2017 | 17/6/2026 | In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file… | |
| Modificada | Media (5.5) | 0.38% | — | Vmware EsxiVmware WorkstationVmware Workstation PROVmware Fusion | 15/9/2017 | 17/6/2026 | VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.4) contain a NULL pointer dereference vulnerability. This issue occurs when handling guest RPC requests. Successful… | |
| Modificada | Alta (8.8) | 0.61% | — | Vmware FusionVmware Workstation PROVmware Esxi | 15/9/2017 | 17/6/2026 | VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. This issue may allow a guest to execute code on the host. | |
| Modificada | Media (5.5) | 1.2% | 💥 Exploit | Vmware FusionVmware Fusion PROVmware Workstation PlayerVmware Workstation PRO+1 | 7/6/2017 | 17/6/2026 | VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have… | |
| Modificada | Alta (8.8) | 0.43% | — | Vmware FusionVmware Fusion PROVmware Workstation PlayerVmware Workstation PRO+1 | 7/6/2017 | 17/6/2026 | The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion… | |
| Modificada | Alta (8.8) | 0.41% | — | Vmware Workstation PlayerVmware Workstation PROVmware EsxiVmware Fusion+1 | 7/6/2017 | 17/6/2026 | VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have… | |
| Modificada | Alta (8.8) | 0.52% | — | Vmware Workstation PlayerVmware Workstation PROVmware EsxiVmware Fusion+1 | 7/6/2017 | 17/6/2026 | VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Buffer Overflow in SVGA. This issue may allow a guest to execute code on the host. | |
| Modificada | Media (5.4) | 1.1% | — | Vmware Esxi | 29/12/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted VM. | |
| Modificada | Media (6.1) | 1.9% | — | Vmware Vcenter ServerVmware Esxi | 8/8/2016 | 17/6/2026 | CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | |
| Modificada | Alta (7.8) | 18% | 💥 Exploit | Vmware Workstation PlayerVmware Workstation PROVmware EsxiVmware Fusion+1 | 8/8/2016 | 17/6/2026 | Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before 8.1.1 allows local users to gain privileges via a Trojan horse… | |
| Modificada | Media (6.3) | 1.3% | — | Vmware PlayerVmware WorkstationVmware EsxiVmware Fusion | 9/1/2016 | 17/6/2026 | The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS users to gain guest OS privileges or cause a denial of service (guest OS kernel memory corruption)… | |
| Modificada | Baja (3.3) | 0.83% | — | Vmware WorkstationVmware EsxiVmware Player | 29/1/2015 | 17/6/2026 | vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allows attackers to cause a host OS denial of service via unspecified vectors. |