Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.7) | 1.9% | — | Vmware Vcenter Server | 18/9/2019 | 17/6/2026 | VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a… | |
| Modificada | Alta (7.5) | 1.5% | — | Netapp Hyper Converged Infrastructure Compute NodeNetapp Element Plug-in FOR Vcenter Server | 29/4/2019 | 17/6/2026 | Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Compute Node versions prior to 1.4P2 bundle affected versions of Element Plug-in for vCenter Server. | |
| Modificada | Alta (7.8) | 0.36% | — | Vmware Vcenter Server | 20/12/2017 | 17/6/2026 | VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the appliance base OS. | |
| Modificada | Alta (7.5) | 1.2% | — | Vmware Vcenter Server | 17/11/2017 | 17/6/2026 | The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a POST request with modified headers towards internal services… | |
| Modificada | Alta (7.5) | 2.3% | — | Vmware Vcenter Server | 17/11/2017 | 17/6/2026 | VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service. | |
| Modificada | Media (5.4) | 0.78% | — | Vmware Vcenter Server | 15/9/2017 | 17/6/2026 | VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page. | |
| Modificada | Crítica (9.8) | 1.9% | — | Vmware Vcenter Server | 1/8/2017 | 17/6/2026 | VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature. | |
| Modificada | Media (6.5) | 1.3% | — | Vmware Vcenter Server | 1/8/2017 | 17/6/2026 | VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the… | |
| Modificada | Alta (8.8) | 1.7% | — | Vmware Vcenter Server | 1/8/2017 | 17/6/2026 | VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation. | |
| Modificada | Crítica (9) | 2.0% | — | Vmware Vcenter Server | 28/7/2017 | 17/6/2026 | VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate. | |
| Modificada | Alta (7.7) | 1.9% | — | Vmware Vcenter Server | 29/12/2016 | 17/6/2026 | VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity… | |
| Modificada | Media (6.1) | 1.9% | — | Vmware Vcenter ServerVmware Esxi | 8/8/2016 | 17/6/2026 | CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | |
| Modificada | Media (6.1) | 0.77% | — | Vmware Vcenter Server | 3/7/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.1) | 1.1% | — | Vmware Vcenter Server | 8/6/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter. | |
| Modificada | Alta (7.6) | 1.4% | — | Vmware Vcenter ServerVmware Vcloud Automation Identity ApplianceVmware Vcloud Director | 15/4/2016 | 17/6/2026 | Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site. | |
| Modificada | Alta (7.3) | 5.0% | — | Vmware Vcenter OrchestratorVmware Vrealize Orchestrator | 21/12/2015 | 17/6/2026 | Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons… | |
| Modificada | Alta (10) | 89% | 💥 Exploit | Vmware Vcenter Server | 12/10/2015 | 17/6/2026 | The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol. | |
| Modificada | Media (5) | 3.3% | — | Vmware Vcenter Server | 12/10/2015 | 17/6/2026 | vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message. | |
| Modificada | Media (5.8) | 0.74% | — | Vmware Vcenter Server | 18/9/2015 | 17/6/2026 | VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 0.59% | — | Vmware Vcenter Server Appliance | 8/12/2014 | 17/6/2026 | VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate. | |
| Modificada | Media (4.3) | 1.8% | — | Vmware Vcenter Server Appliance | 8/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | GNU BashArista EOSOracle LinuxQnap QTS+70 | 25/9/2014 | 17/6/2026 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | GNU BashArista EOSOracle LinuxQnap QTS+70 | 24/9/2014 | 17/6/2026 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the… | |
| Modificada | Media (6.5) | 3.5% | — | Oracle MysqlVmware Vcenter Server ApplianceOracle SolarisOpensuse Project Suse Linux Enterprise Desktop+8 | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC. | |
| Modificada | Media (4.3) | 3.8% | — | Vmware Vcenter ServerVmware Vcenter Server ApplianceVmware EsxiOracle Fusion Middleware | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related to WLS - Web Services. |