Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

124 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9)2.4%—Vmware Vcenter Server Appliance1/6/201417/6/2026
Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail.
ModificadaMedia (6.8)2.0%—Vmware Vcenter Server21/10/201316/6/2026
Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.
ModificadaAlta (7.5)56%💥 ExploitVmware Vcenter Chargeback Manager17/6/201316/6/2026
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (4.3)2.0%—Vmware Vcenter Server Appliance1/5/201316/6/2026
VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid username in conjunction with an empty password.
ModificadaAlta (9)2.5%—Vmware Vcenter Server Appliance1/5/201316/6/2026
VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently execute arbitrary code or cause a denial of service, by leveraging Virtual Appliance Management Interface (VAMI) web-interface access.
ModificadaAlta (9)1.7%—Vmware Vcenter Server Appliance1/5/201316/6/2026
VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Management Interface (VAMI) access.
ModificadaAlta (7.6)1.8%—Vmware Vcenter ServerVmware Vcenter Server ApplianceVmware Esxi22/2/201316/6/2026
VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory…
ModificadaAlta (7.8)1.3%—Vmware Vcenter ServerVmware Vcenter Server Appliance22/2/201316/6/2026
VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors that trigger large log entries.
ModificadaAlta (10)2.8%—Vmware Vcenter ServerVmware VirtualcenterVmware Vsphere ClientVmware Vi-client+215/2/201316/6/2026
VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which…
ModificadaMedia (4)0.95%—Vmware Vcenter Server Appliance21/12/201216/6/2026
VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 does not properly parse XML documents, which allows remote authenticated users to read arbitrary files via unspecified vectors.
ModificadaMedia (4)1.5%—Vmware Vcenter Server Appliance21/12/201216/6/2026
Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files via unspecified vectors.
ModificadaMedia (4.3)2.0%—Vmware Vcenter Operations5/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in the server in VMware vCenter Operations (aka vCOps) before 5.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4)1.2%—Vmware Vcenter Orchestrator16/3/201216/6/2026
The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document.
ModificadaMedia (6.4)1.9%—Vmware Vcenter Chargeback Manager13/3/201216/6/2026
VMware vCenter Chargeback Manager (aka CBM) before 2.0.1 does not properly handle XML API requests, which allows remote attackers to read arbitrary files or cause a denial of service via unspecified vectors.
ModificadaMedia (5)60%💥 ExploitVmware Vcenter Update Manager19/11/201116/6/2026
The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523.
ModificadaMedia (5)1.9%—Vmware ESXVmware EsxiVmware Vcenter9/5/201116/6/2026
The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1 Update 1 does not have a digital signature, which might make it easier for remote attackers to spoof the software…
ModificadaBaja (2.1)0.37%—Vmware Vcenter9/5/201116/6/2026
vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.
ModificadaMedia (4.3)2.1%—Vmware VcenterVmware Virtualcenter9/5/201116/6/2026
Directory traversal vulnerability in vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, and VMware VirtualCenter 2.5 before Update 6a, allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaBaja (2.1)0.36%—Vmware Vcenter Server16/2/201116/6/2026
The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileges by reading this file.
ModificadaMedia (4.3)2.8%—Webworks EpublisherWebworks HelpWebworks PublisherVmware Vcenter+616/12/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x…
ModificadaAlta (7.8)7.1%💥 ExploitLinux KernelCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+827/8/200916/6/2026
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.
ModificadaMedia (6.5)1.8%—Xmlsoft LibxmlXmlsoft Libxml2Fedoraproject FedoraDebian Linux+1511/8/200916/6/2026
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing…
ModificadaMedia (4.9)0.43%—Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+725/3/200916/6/2026
nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
ModificadaAlta (7.1)4.6%—Linux KernelVmware VcenterVmware VirtualcenterVmware Server+212/3/200916/6/2026
The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to…