Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1256 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.25% | — | Vmware Spring AI | 27/3/2026 | 17/6/2026 | In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG block without escaping characters.This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0… | |
| Analizada | Alta (7.5) | 0.25% | — | Vmware Spring AI | 27/3/2026 | 17/6/2026 | Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is passed as a filter expression key in Neo4jVectorFilterExpressionConverter of spring-ai-neo4j-store, doKey() embeds the key into a backtick-delimited Cypher property… | |
| Modificada | Alta (8.6) | 0.35% | — | Vmware Spring AI | 27/3/2026 | 17/6/2026 | Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requests to unintended… | |
| Modificada | Crítica (9.8) | 1.1% | 💥 PoC | Vmware Spring AI | 27/3/2026 | 17/6/2026 | In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression key are affected. This… | |
| En análisis | Alta (8.6) | 1.2% | 💥 Exploit | Vmware Spring Cloud Config | 24/3/2026 | 4/9/2026 | Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13,… | |
| Analizada | Media (5.9) | 0.39% | — | Vmware Spring Framework | 20/3/2026 | 17/6/2026 | Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16,… | |
| Analizada | Baja (2.6) | 0.11% | — | Vmware Spring Framework | 20/3/2026 | 17/6/2026 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46. | |
| Analizada | Alta (8.1) | 0.36% | — | Vmware Spring Boot | 20/3/2026 | 17/6/2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11,… | |
| Analizada | Crítica (9.1) | 0.48% | 💥 PoC | Vmware Spring Security | 19/3/2026 | 17/6/2026 | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through… | |
| Analizada | Alta (8.1) | 0.33% | — | Vmware Spring Boot | 19/3/2026 | 17/6/2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before… | |
| Analizada | Alta (8.8) | 0.52% | 💥 PoC | Vmware Spring AI | 18/3/2026 | 17/6/2026 | A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization. | |
| Analizada | Alta (8.6) | 0.53% | — | Vmware Spring AI | 18/3/2026 | 17/6/2026 | A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated into JSONPath queries without proper escaping, enabling… | |
| Aplazada | Baja (2.7) | 0.17% | — | Vmware WorkstationAI | 27/2/2026 | 17/6/2026 | Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed. | |
| Aplazada | Media (5) | 0.16% | — | Vmware WorkstationAI | 27/2/2026 | 17/6/2026 | Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to terminate certain Workstation processes. | |
| Aplazada | Media (5.9) | 0.21% | — | Vmware WorkstationAIVmware FusionAI | 26/2/2026 | 17/6/2026 | VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's. Resolution: To remediate CVE-2026-22715 please upgrade to VMware… | |
| Analizada | Alta (7.2) | 0.71% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of… | |
| Analizada | Crítica (9) | 0.42% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the… | |
| Analizada | Alta (8.1) | 18% | ⚠ Explotación activa | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the… | |
| Aplazada | Alta (8.2) | 0.38% | — | Vmware Data GeodeAI | 20/2/2026 | 15/7/2026 | A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only. | |
| Aplazada | Media (4.8) | 0.14% | — | Vmware Data GeodeAI | 19/2/2026 | 17/6/2026 | Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data. | |
| Aplazada | Baja (2) | 0.11% | — | Vmware EsxiAIIntel Ethernet 800 SeriesAI | 10/2/2026 | 17/6/2026 | Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack… | |
| Aplazada | Media (5.3) | 0.40% | — | Vmware SecurityAI | 22/1/2026 | 17/6/2026 | The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations. | |
| Aplazada | Media (6.8) | 0.59% | — | Microsoft VscodeAIVmware CLIAI | 14/1/2026 | 17/6/2026 | The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine. | |
| Aplazada | Media (4.3) | 0.31% | — | Vmware Spring FrameworkAI | 16/10/2025 | 17/6/2026 | STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: MitigationUsers of affected versions should upgrade to the corresponding fixed version. Affected version(s)Fix… | |
| Aplazada | Alta (7.5) | 0.48% | — | Vmware Cloud Gateway Server WebfluxAI | 16/10/2025 | 17/6/2026 | The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers. An application should be considered vulnerable when all the following are true: |