Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.39% | — | Vmware Horizon Client | 15/6/2020 | 17/6/2026 | VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe loading of libraries. A local user on the system where the software is installed may exploit this issue to run commands as any user. | |
| Modificada | Alta (7) | 0.22% | — | Vmware FusionVmware Horizon ClientVmware Remote Console | 29/5/2020 | 17/6/2026 | VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with… | |
| Modificada | Alta (8.8) | 3.5% | — | Opennms HorizonOpennms Meridian | 11/5/2020 | 17/6/2026 | An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objects (aka ActiveMQ Minion payload deserialization), leading to remote code execution for any authenticated channel user… | |
| Modificada | Alta (8.1) | 1.4% | — | Opennms HorizonOpennms Meridian | 17/4/2020 | 17/6/2026 | OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or snmpParmValue to addCriteriaForSnmpParm. This affects Horizon before 25.2.1, Meridian 2019 before 2019.1.4, Meridian 2018 before 2018.1.16, and Meridian 2017 before 2017.1.21. | |
| Modificada | Baja (3.8) | 0.27% | — | Vmware Horizon ClientVmware Workstation | 17/3/2020 | 17/6/2026 | VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-service vulnerability due to a heap-overflow issue in Cortado Thinprint. Attackers with non-administrative access to a guest VM with virtual printing enabled may exploit this issue to create a… | |
| Analizada | Alta (7.8) | 7.3% | ⚠ Explotación activa💥 Exploit | Vmware FusionVmware Horizon ClientVmware Remote Console | 17/3/2020 | 17/6/2026 | VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user… | |
| Modificada | Alta (7.8) | 0.39% | — | Vmware Horizon ClientVmware Remote ConsoleVmware Workstation | 16/3/2020 | 17/6/2026 | For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing configuration files for the VMware USB arbitration service was found to be writable by all users. A local user on the… | |
| Modificada | Media (5.5) | 0.40% | — | Openstack HorizonDebian Linux | 30/12/2019 | 16/6/2026 | Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value. | |
| Modificada | Media (5.5) | 0.34% | — | Redhat OpenstackOpenstack HorizonDebian LinuxFedoraproject Fedora | 30/12/2019 | 16/6/2026 | The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value. | |
| Modificada | Alta (7.8) | 0.43% | — | Vmware Horizon View AgentVmware Workstation | 23/12/2019 | 17/6/2026 | VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Vmware Horizon DaasVmware EsxiRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+12 | 6/12/2019 | 17/6/2026 | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8. | |
| Modificada | Alta (8.8) | 0.30% | — | Vmware HorizonVmware Remote ConsoleVmware WorkstationVmware Fusion+1 | 10/10/2019 | 17/6/2026 | ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5. | |
| Modificada | Alta (7.8) | 0.33% | — | Mckesson Horizon Cardiology FirmwareMckesson Cardiology FirmwareChangehealthcare Cardiology Firmware | 6/9/2019 | 17/6/2026 | A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default installation may allow an attacker with local system access to execute unauthorized arbitrary code. | |
| Modificada | Media (5.3) | 1.2% | 💥 PoC | Vmware Horizon | 9/4/2019 | 17/6/2026 | VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosure vulnerability. Successful exploitation of this issue may allow disclosure of internal domain names, the Connection Server’s internal name, or the gateway’s internal IP address. | |
| Modificada | Media (6.5) | 1.8% | — | Vmware Horizon ClientVmware Horizon View | 13/8/2018 | 17/6/2026 | VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1) contain an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less-privileged user to leak information from a privileged process… | |
| Modificada | Alta (7.8) | 0.42% | — | Vmware Horizon View Agents | 25/7/2018 | 17/6/2026 | VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (including silent installations). Successful exploitation of this… | |
| Modificada | Alta (7.8) | 0.38% | — | Vmware Horizon Client | 29/5/2018 | 17/6/2026 | VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local privilege escalation vulnerability due to insecure usage of SUID binary. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on a Linux machine where Horizon Client is installed. | |
| Modificada | Alta (8.8) | 2.5% | — | Vmware Horizon Daas | 20/4/2018 | 17/6/2026 | VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS. | |
| Modificada | Alta (7.1) | 0.41% | — | Vmware WorkstationVmware Horizon View | 5/1/2018 | 17/6/2026 | VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll. On Workstation, this issue in conjunction with other bugs may allow a guest to leak information from host or may allow for a Denial of Service on the Windows OS that… | |
| Modificada | Alta (7.8) | 0.50% | — | Vmware Vrealize Operations FOR HorizonVmware Vrealize Operations FOR Published Applications | 5/1/2018 | 17/6/2026 | The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM. | |
| Modificada | Alta (7.8) | 0.39% | — | Vmware WorkstationVmware Horizon View | 17/11/2017 | 17/6/2026 | VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of… | |
| Modificada | Alta (7.8) | 0.39% | — | Vmware WorkstationVmware Horizon View | 17/11/2017 | 17/6/2026 | VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of… | |
| Modificada | Alta (7.8) | 0.39% | — | Vmware WorkstationVmware Horizon View | 17/11/2017 | 17/6/2026 | VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of… | |
| Modificada | Crítica (9.8) | 4.9% | — | Vmware Horizon View | 8/6/2017 | 17/6/2026 | VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on the Mac OSX system where the client is installed. | |
| Modificada | Alta (7.8) | 0.39% | — | Vmware Horizon ViewVmware Workstation | 8/6/2017 | 17/6/2026 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the True Type Font parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of… |