Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 56% | 💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+1 | 20/5/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. | |
| Modificada | Crítica (9.8) | 6.7% | — | Microsoft Workspace-tools | 13/5/2022 | 17/6/2026 | The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch subcommand in a way that additional flags can… | |
| Modificada | Alta (7.8) | 2.1% | — | IBM Planning Analytics Workspace | 25/4/2022 | 17/6/2026 | IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066. | |
| Modificada | Alta (8) | 0.78% | — | IBM Planning Analytics Workspace | 25/4/2022 | 17/6/2026 | IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 214025. | |
| Modificada | Media (5.3) | 0.85% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims. | |
| Analizada | Alta (7.8) | 36% | ⚠ Explotación activa💥 Exploit | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'. | |
| Modificada | Media (4.3) | 0.51% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI. | |
| Modificada | Alta (7.2) | 3.1% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution. | |
| Modificada | Alta (7.2) | 24% | 💥 Exploit | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution. | |
| Modificada | Crítica (9.8) | 50% | 💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework. | |
| Modificada | Crítica (9.8) | 7.8% | — | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+1 | 11/4/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. | |
| Modificada | Media (5.4) | 0.46% | — | Vmware Workspace ONE Boxer | 2/3/2022 | 17/6/2026 | VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary script within a user's window. | |
| Modificada | Alta (7.8) | 0.22% | — | Citrix Workspace | 9/2/2022 | 17/6/2026 | An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation. | |
| Modificada | Media (5.5) | 0.35% | — | Ivanti Workspace Control | 10/1/2022 | 17/6/2026 | A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector. | |
| Modificada | Alta (8.8) | 1.1% | — | Vmware Workspace ONE Access | 20/12/2021 | 17/6/2026 | VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify. | |
| Modificada | Alta (7.5) | 1.6% | — | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access | 20/12/2021 | 17/6/2026 | VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Workspace ONE UEM Console | 17/12/2021 | 1/10/2026 | VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to… | |
| Modificada | Alta (7.5) | 2.1% | — | Ivanti Workspace Control | 15/12/2021 | 17/6/2026 | Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity. | |
| Modificada | Alta (7.2) | 1.1% | — | Siemens Teamcenter Active Workspace | 14/12/2021 | 17/6/2026 | A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.11), Teamcenter Active Workspace V5.0 (All versions < V5.0.10), Teamcenter Active Workspace V5.1 (All versions < V5.1.6), Teamcenter Active Workspace V5.2 (All versions < V5.2.3). The application contains an unsafe unzipping… | |
| Modificada | Alta (8.8) | 0.55% | — | Amazon Workspaces | 7/12/2021 | 17/6/2026 | Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Alta (8.8) | 0.48% | — | Amazon Workspaces | 7/12/2021 | 17/6/2026 | Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Alta (7) | 0.26% | 💥 PoC | Sophos Secure Workspace | 30/10/2021 | 17/6/2026 | A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115. | |
| Modificada | Alta (8.8) | 7.5% | — | Amazon AWS Workspaces | 22/9/2021 | 17/6/2026 | In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote code execution because of the Chromium Embedded Framework (CEF) --gpu-launcher argument. This is fixed in 3.1.9. | |
| Modificada | Media (4.9) | 1.2% | — | Siemens Teamcenter Active Workspace | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.10), Teamcenter Active Workspace V5.0 (All versions < V5.0.8), Teamcenter Active Workspace V5.1 (All versions < V5.1.5), Teamcenter Active Workspace V5.2 (All versions < V5.2.1). A path traversal vulnerability in the… |