Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9) | 2.4% | — | Vmware Vcenter Server Appliance | 1/6/2014 | 17/6/2026 | Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail. | |
| Modificada | Media (6.8) | 2.0% | — | Vmware Vcenter Server | 21/10/2013 | 16/6/2026 | Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors. | |
| Modificada | Alta (7.5) | 56% | 💥 Exploit | Vmware Vcenter Chargeback Manager | 17/6/2013 | 16/6/2026 | VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Vmware Vcenter Server Appliance | 1/5/2013 | 16/6/2026 | VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid username in conjunction with an empty password. | |
| Modificada | Alta (9) | 2.5% | — | Vmware Vcenter Server Appliance | 1/5/2013 | 16/6/2026 | VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently execute arbitrary code or cause a denial of service, by leveraging Virtual Appliance Management Interface (VAMI) web-interface access. | |
| Modificada | Alta (9) | 1.7% | — | Vmware Vcenter Server Appliance | 1/5/2013 | 16/6/2026 | VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Management Interface (VAMI) access. | |
| Modificada | Alta (7.6) | 1.8% | — | Vmware Vcenter ServerVmware Vcenter Server ApplianceVmware Esxi | 22/2/2013 | 16/6/2026 | VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory… | |
| Modificada | Alta (7.8) | 1.3% | — | Vmware Vcenter ServerVmware Vcenter Server Appliance | 22/2/2013 | 16/6/2026 | VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors that trigger large log entries. | |
| Modificada | Alta (10) | 2.8% | — | Vmware Vcenter ServerVmware VirtualcenterVmware Vsphere ClientVmware Vi-client+2 | 15/2/2013 | 16/6/2026 | VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which… | |
| Modificada | Media (4) | 0.95% | — | Vmware Vcenter Server Appliance | 21/12/2012 | 16/6/2026 | VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 does not properly parse XML documents, which allows remote authenticated users to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4) | 1.5% | — | Vmware Vcenter Server Appliance | 21/12/2012 | 16/6/2026 | Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Vmware Vcenter Operations | 5/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the server in VMware vCenter Operations (aka vCOps) before 5.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.2% | — | Vmware Vcenter Orchestrator | 16/3/2012 | 16/6/2026 | The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document. | |
| Modificada | Media (6.4) | 1.9% | — | Vmware Vcenter Chargeback Manager | 13/3/2012 | 16/6/2026 | VMware vCenter Chargeback Manager (aka CBM) before 2.0.1 does not properly handle XML API requests, which allows remote attackers to read arbitrary files or cause a denial of service via unspecified vectors. | |
| Modificada | Media (5) | 60% | 💥 Exploit | Vmware Vcenter Update Manager | 19/11/2011 | 16/6/2026 | The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523. | |
| Modificada | Media (5) | 1.9% | — | Vmware ESXVmware EsxiVmware Vcenter | 9/5/2011 | 16/6/2026 | The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1 Update 1 does not have a digital signature, which might make it easier for remote attackers to spoof the software… | |
| Modificada | Baja (2.1) | 0.37% | — | Vmware Vcenter | 9/5/2011 | 16/6/2026 | vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors. | |
| Modificada | Media (4.3) | 2.1% | — | Vmware VcenterVmware Virtualcenter | 9/5/2011 | 16/6/2026 | Directory traversal vulnerability in vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, and VMware VirtualCenter 2.5 before Update 6a, allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.36% | — | Vmware Vcenter Server | 16/2/2011 | 16/6/2026 | The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileges by reading this file. | |
| Modificada | Media (4.3) | 2.8% | — | Webworks EpublisherWebworks HelpWebworks PublisherVmware Vcenter+6 | 16/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x… | |
| Modificada | Alta (7.8) | 7.1% | 💥 Exploit | Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+8 | 27/8/2009 | 16/6/2026 | The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket. | |
| Modificada | Media (6.5) | 1.8% | — | Xmlsoft LibxmlXmlsoft Libxml2Fedoraproject FedoraDebian Linux+15 | 11/8/2009 | 16/6/2026 | Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing… | |
| Modificada | Media (4.9) | 0.43% | — | Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+7 | 25/3/2009 | 16/6/2026 | nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option. | |
| Modificada | Alta (7.1) | 4.6% | — | Linux KernelVmware VcenterVmware VirtualcenterVmware Server+2 | 12/3/2009 | 16/6/2026 | The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to… |