Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.2) | 0.10% | — | Vmware EsxiAI | 13/5/2026 | 30/9/2026 | An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability. | |
| Pendiente de análisis | Alta (8.8) | 0.11% | — | Vmware EsxiAI | 13/5/2026 | 30/9/2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Pendiente de análisis | Alta (8.8) | 0.10% | — | Vmware EsxiAI | 13/5/2026 | 30/9/2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Pendiente de análisis | Alta (8.3) | 0.12% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially… | |
| Pendiente de análisis | Crítica (9.3) | 0.13% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may… | |
| Pendiente de análisis | Alta (8.3) | 0.12% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur… | |
| Aplazada | Baja (2) | 0.11% | — | Vmware EsxiAIIntel Ethernet 800 SeriesAI | 10/2/2026 | 17/6/2026 | Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack… | |
| Aplazada | Alta (7.1) | 3.0% | — | Vmware EsxiAIVmware WorkstationAIVmware FusionAIVmware ToolsAI | 15/7/2025 | 17/6/2026 | VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with… | |
| Aplazada | Crítica (9.3) | 0.46% | — | Vmware EsxiAIVmware WorkstationAIVmware FusionAI | 15/7/2025 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process… | |
| Aplazada | Crítica (9.3) | 0.46% | — | Vmware EsxiAIVmware WorkstationAIVmware FusionAI | 15/7/2025 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on… | |
| Aplazada | Crítica (9.3) | 2.6% | — | Vmware EsxiAIVmware WorkstationAIVmware FusionAI | 15/7/2025 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are… | |
| Aplazada | Media (4.3) | 0.89% | — | Vmware EsxiAIVmware Vcenter ServerAI | 20/5/2025 | 17/6/2026 | VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites. | |
| Aplazada | Media (5.5) | 0.16% | — | Vmware EsxiAIVmware WorkstationAIVmware FusionAI | 20/5/2025 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition. | |
| Aplazada | Media (6.8) | 0.24% | — | Vmware EsxiAIVmware Vcenter ServerAIVmware ToolsAI | 20/5/2025 | 17/6/2026 | VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools… | |
| Analizada | Media (6) | 1.8% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware FusionVmware Telco Cloud Infrastructure+2 | 4/3/2025 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | |
| Analizada | Alta (8.2) | 1.0% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/3/2025 | 4/8/2026 | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. | |
| Analizada | Alta (8.2) | 1.6% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform+1 | 4/3/2025 | 17/6/2026 | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. | |
| Analizada | Media (6.8) | 0.19% | — | Vmware Cloud FoundationVmware Esxi | 25/6/2024 | 17/6/2026 | VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host. | |
| Analizada | Alta (7.2) | 27% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Esxi | 25/6/2024 | 17/6/2026 | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by… | |
| Modificada | Alta (7.8) | 0.17% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 21/5/2024 | 17/6/2026 | The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in… | |
| Analizada | Alta (7.1) | 2.3% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | |
| Analizada | Alta (8.2) | 0.50% | — | Vmware Cloud FoundationVmware Esxi | 5/3/2024 | 17/6/2026 | VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox. | |
| Analizada | Media (6.7) | 0.65% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained… | |
| Modificada | Media (6.7) | 3.5% | — | Vmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained… | |
| Analizada | Alta (7.5) | 64% | ⚠ Explotación activa | Netapp Smi-s ProviderSuse Manager ServerSuse Linux Enterprise ServerVmware Esxi+1 | 25/4/2023 | 17/6/2026 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor. |