Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.33% | — | Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector | 5/8/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | |
| Modificada | Media (6.1) | 0.67% | — | Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector | 5/8/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window. | |
| Modificada | Alta (7.5) | 1.2% | — | Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector | 5/8/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files. | |
| Modificada | Alta (7.8) | 0.33% | — | Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector | 5/8/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'. | |
| Modificada | Alta (7.8) | 1.1% | — | Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector | 5/8/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | |
| Modificada | Alta (7.2) | 2.9% | — | Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector | 5/8/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. | |
| Modificada | Alta (7.2) | 2.2% | — | Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector | 5/8/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. | |
| Modificada | Crítica (9.8) | 1.4% | — | Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector | 5/8/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain. | |
| Modificada | Crítica (9.8) | 24% | — | Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector | 5/8/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. | |
| Modificada | Media (6.5) | 0.36% | — | Teradici Cloud Access Connector | 11/2/2021 | 17/6/2026 | An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link. | |
| Modificada | Media (6.5) | 1.0% | — | Teradici Cloud Access Connector | 11/2/2021 | 17/6/2026 | Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the need to specify authentication tokens, which allowed an attacker in the ability to execute sensitive functions without credentials. | |
| Modificada | Media (6.1) | 0.83% | — | Teradici Cloud Access ConnectorTeradici Cloud Access Connector Legacy | 11/8/2020 | 17/6/2026 | The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 24, 2020 (v16 and earlier for the Cloud Access Connector) contains a stored cross-site scripting (XSS) vulnerability which allows a remote unauthenticated attacker to poison log files with… | |
| Modificada | Alta (7.5) | 1.7% | — | Teradici Cloud Access ConnectorTeradici Cloud Access Connector Legacy | 11/8/2020 | 17/6/2026 | The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local file inclusion vulnerability which allows an unauthenticated remote attacker to leak LDAP credentials via a specially… |