Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1254 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 0.36% | — | Vmware Spring Security | 26/8/2026 | 4/9/2026 | An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 | |
| Analizada | Crítica (9.8) | 0.55% | — | Vmware Spring Cloud Config | 26/8/2026 | 4/9/2026 | Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14. | |
| Analizada | Alta (8.1) | 0.22% | — | Vmware Spring Cloud Config | 26/8/2026 | 4/9/2026 | The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14… | |
| Aplazada | Media (5.9) | 0.54% | — | Vmware VeleroAI | 25/8/2026 | 9/9/2026 | Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that escape the extraction directory during… | |
| Aplazada | Crítica (9.8) | 0.88% | — | Beijing Tongtech TongwebAIVmware HttpinvokerserviceexporterAI | 25/8/2026 | 31/8/2026 | An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint | |
| Analizada | Alta (7.4) | 0.39% | — | Vmware Spring Security | 25/8/2026 | 24/9/2026 | Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server… | |
| Analizada | Crítica (9.8) | 0.25% | — | Vmware Spring AI | 21/8/2026 | 16/9/2026 | In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation. Affected… | |
| Analizada | Media (4.3) | 0.22% | — | Vmware Spring AI | 21/8/2026 | 16/9/2026 | In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0 | |
| Analizada | Alta (7.5) | 0.55% | — | Vmware Spring AI | 21/8/2026 | 16/9/2026 | The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually… | |
| Pendiente de análisis | Baja (2.7) | 0.30% | — | Vmware ESXAI | 30/7/2026 | 30/7/2026 | VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged. | |
| Analizada | Crítica (9.8) | 2.6% | ⚠ Explotación activa💥 PoC | Vmware Vcenter Server | 30/7/2026 | 19/8/2026 | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. | |
| Analizada | Crítica (9.8) | 0.61% | — | Vmware Vcenter Server | 30/7/2026 | 25/8/2026 | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system. | |
| Pendiente de análisis | Crítica (9.3) | 0.19% | — | Vmware ESXAIVmware Vmxnet3AI | 30/7/2026 | 30/7/2026 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this… | |
| Pendiente de análisis | Alta (7.6) | 0.43% | — | Vmware ESXAIVmware WorkstationAIVmware FusionAI | 30/7/2026 | 30/7/2026 | VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the… | |
| Pendiente de análisis | Crítica (9.2) | 0.50% | — | Synopsys Coverity ConnectAIVmware Spring SecurityAI | 29/7/2026 | 30/7/2026 | A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data… | |
| Analizada | Alta (8.8) | 0.96% | — | Broadcom Vmware AVI Load Balancer | 18/7/2026 | 20/8/2026 | VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7)… | |
| Analizada | Alta (8.8) | 0.42% | — | Broadcom Vmware AVI Load Balancer | 18/7/2026 | 20/8/2026 | VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in… | |
| Analizada | Alta (8.8) | 0.74% | — | Broadcom Vmware AVI Load Balancer | 18/7/2026 | 20/8/2026 | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7… | |
| Analizada | Alta (7.8) | 0.14% | — | Broadcom Vmware AVI Load Balancer | 18/7/2026 | 20/8/2026 | VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through… | |
| Analizada | Alta (8.8) | 0.74% | — | Broadcom Vmware AVI Load Balancer | 18/7/2026 | 20/8/2026 | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1… | |
| Analizada | Alta (8.3) | 0.38% | — | Broadcom Vmware AVI Load Balancer | 18/7/2026 | 20/8/2026 | VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7)… | |
| Analizada | Crítica (9.8) | 0.61% | — | Broadcom Vmware AVI Load Balancer | 18/7/2026 | 20/8/2026 | VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through… | |
| Aplazada | Alta (7.7) | 0.48% | — | Vmware Boot Admin ServerAI | 13/7/2026 | 15/7/2026 | Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against private IP ranges or metadata endpoints. Attackers can force the server to… | |
| Pendiente de análisis | Baja (3.8) | 0.27% | — | Vmware PinnipedAI | 9/7/2026 | 9/7/2026 | A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions were true: the Pinniped Supervisor server is running with an ActiveDirectoryIdentityProvider resource configured; the… | |
| Pendiente de análisis | Crítica (9.8) | 1.1% | 💥 PoC | Vmware CRMAI | 1/7/2026 | 2/7/2026 | An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services.Conversion.dll component. NOTE: this issue exists because of an incomplete fix… |