Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.20% | — | Oracle Cloud Infrastructure CLI | 6/5/2026 | 17/6/2026 | Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitable vulnerability allows unauthenticated attacker with network access to compromise Oracle OCI CLI. Successful attacks of this vulnerability can result in Oracle OCI CLI allowing… | |
| Analizada | Alta (7.2) | 0.71% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of… | |
| Analizada | Crítica (9) | 0.42% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the… | |
| Analizada | Alta (8.1) | 18% | ⚠ Explotación activa | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the… | |
| Analizada | Alta (7.8) | 8.4% | ⚠ Explotación activa💥 PoC | Vmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+4 | 29/9/2025 | 17/6/2026 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the… | |
| Aplazada | Alta (7.5) | 0.61% | — | Cloud Infrastructure Services Cloud Saml SSO Single Sign ONAI | 14/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cloud Infrastructure Services Cloud SAML SSO - Single Sign On Login cloud-sso-single-sign-on allows PHP Local File Inclusion.This issue affects Cloud SAML SSO - Single Sign On Login: from n/a… | |
| Analizada | Media (5.9) | 0.26% | — | Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/6/2025 | 17/6/2026 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. | |
| Analizada | Media (6.9) | 0.31% | — | Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/6/2025 | 17/6/2026 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation. | |
| Analizada | Alta (7.5) | 0.34% | — | Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/6/2025 | 17/6/2026 | VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. | |
| Analizada | Media (6) | 1.8% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware FusionVmware Telco Cloud Infrastructure+2 | 4/3/2025 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | |
| Analizada | Alta (8.2) | 1.0% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/3/2025 | 4/8/2026 | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. | |
| Analizada | Alta (8.2) | 1.6% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform+1 | 4/3/2025 | 17/6/2026 | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. | |
| Modificada | Baja (3.7) | 0.50% | — | Jenkins Cloud Infrastructure Compute | 12/7/2023 | 17/6/2026 | Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not validate SSH host keys when connecting OCI clouds, enabling man-in-the-middle attacks. | |
| Modificada | Media (4.9) | 0.84% | — | Oracle Cloud Infrastructure | 17/6/2022 | 17/6/2026 | Vulnerability in the Oracle Cloud Infrastructure product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access to compromise Oracle Cloud Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to Oracle Cloud Infrastructure… | |
| Modificada | Crítica (9.1) | 1.1% | — | Oracle Cloud Infrastructure Storage Gateway | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Management Console). The supported version that is affected is Prior to 1.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cloud… | |
| Modificada | Crítica (9.1) | 1.1% | — | Oracle Cloud Infrastructure Storage Gateway | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Management Console). The supported version that is affected is Prior to 1.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cloud… | |
| Modificada | Crítica (9.1) | 1.1% | — | Oracle Cloud Infrastructure Storage Gateway | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Management Console). The supported version that is affected is Prior to 1.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cloud… | |
| Modificada | Crítica (10) | 1.9% | — | Oracle Cloud Infrastructure Storage Gateway | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Management Console). The supported version that is affected is Prior to 1.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Cloud… | |
| Modificada | Media (4.6) | 0.46% | — | Oracle Cloud Infrastructure Data Science | 3/3/2021 | 17/6/2026 | Vulnerability in the Oracle Cloud Infrastructure Data Science Notebook Sessions. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Cloud Infrastructure Data Science Notebook Sessions executes to compromise Oracle… | |
| Modificada | Media (4.7) | 0.84% | — | Oracle Cloud Infrastructure Identity AND Access Management | 22/12/2020 | 17/6/2026 | Vulnerability in the Oracle Cloud Infrastructure Identity and Access Management product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access to compromise Oracle Cloud Infrastructure Identity and Access Management. Successful attacks of this vulnerability can… | |
| Modificada | Media (4.3) | 0.61% | — | Jenkins Oracle Cloud Infrastructure Compute Classic | 16/10/2019 | 17/6/2026 | A missing permission check in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.62% | — | Jenkins Oracle Cloud Infrastructure Compute Classic | 16/10/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials. |