Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)56%💥 ExploitVmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+120/5/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
ModificadaCrítica (9.8)6.7%—Microsoft Workspace-tools13/5/202217/6/2026
The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch subcommand in a way that additional flags can…
ModificadaAlta (7.8)2.1%—IBM Planning Analytics Workspace25/4/202217/6/2026
IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066.
ModificadaAlta (8)0.78%—IBM Planning Analytics Workspace25/4/202217/6/2026
IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 214025.
ModificadaMedia (5.3)0.85%—Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+113/4/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims.
AnalizadaAlta (7.8)36%⚠ Explotación activa💥 ExploitVmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+113/4/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.
ModificadaMedia (4.3)0.51%—Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+113/4/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.
ModificadaAlta (7.2)3.1%—Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+113/4/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.
ModificadaAlta (7.2)24%💥 ExploitVmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+113/4/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.
ModificadaCrítica (9.8)50%💥 ExploitVmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access13/4/202217/6/2026
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
ModificadaCrítica (9.8)7.8%—Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access13/4/202217/6/2026
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+111/4/202217/6/2026
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
ModificadaMedia (5.4)0.46%—Vmware Workspace ONE Boxer2/3/202217/6/2026
VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary script within a user's window.
ModificadaAlta (7.8)0.22%—Citrix Workspace9/2/202217/6/2026
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.
ModificadaMedia (5.5)0.35%—Ivanti Workspace Control10/1/202217/6/2026
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.
ModificadaAlta (8.8)1.1%—Vmware Workspace ONE Access20/12/202117/6/2026
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.
ModificadaAlta (7.5)1.6%—Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access20/12/202117/6/2026
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitVmware Workspace ONE UEM Console17/12/20211/10/2026
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to…
ModificadaAlta (7.5)2.1%—Ivanti Workspace Control15/12/202117/6/2026
Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.
ModificadaAlta (7.2)1.1%—Siemens Teamcenter Active Workspace14/12/202117/6/2026
A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.11), Teamcenter Active Workspace V5.0 (All versions < V5.0.10), Teamcenter Active Workspace V5.1 (All versions < V5.1.6), Teamcenter Active Workspace V5.2 (All versions < V5.2.3). The application contains an unsafe unzipping…
ModificadaAlta (8.8)0.55%—Amazon Workspaces7/12/202117/6/2026
Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
ModificadaAlta (8.8)0.48%—Amazon Workspaces7/12/202117/6/2026
Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
ModificadaAlta (7)0.26%💥 PoCSophos Secure Workspace30/10/202117/6/2026
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.
ModificadaAlta (8.8)7.5%—Amazon AWS Workspaces22/9/202117/6/2026
In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote code execution because of the Chromium Embedded Framework (CEF) --gpu-launcher argument. This is fixed in 3.1.9.
ModificadaMedia (4.9)1.2%—Siemens Teamcenter Active Workspace14/9/202117/6/2026
A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.10), Teamcenter Active Workspace V5.0 (All versions < V5.0.8), Teamcenter Active Workspace V5.1 (All versions < V5.1.5), Teamcenter Active Workspace V5.2 (All versions < V5.2.1). A path traversal vulnerability in the…