Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

156 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.2)0.10%—Vmware EsxiAI13/5/202630/9/2026
An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability.
Pendiente de análisisAlta (8.8)0.11%—Vmware EsxiAI13/5/202630/9/2026
A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
Pendiente de análisisAlta (8.8)0.10%—Vmware EsxiAI13/5/202630/9/2026
A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
Pendiente de análisisAlta (8.3)0.12%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially…
Pendiente de análisisCrítica (9.3)0.13%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may…
Pendiente de análisisAlta (8.3)0.12%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur…
AplazadaBaja (2)0.11%—Vmware EsxiAIIntel Ethernet 800 SeriesAI10/2/202617/6/2026
Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack…
AplazadaAlta (7.1)3.0%—Vmware EsxiAIVmware WorkstationAIVmware FusionAIVmware ToolsAI15/7/202517/6/2026
VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with…
AplazadaCrítica (9.3)0.46%—Vmware EsxiAIVmware WorkstationAIVmware FusionAI15/7/202517/6/2026
VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process…
AplazadaCrítica (9.3)0.46%—Vmware EsxiAIVmware WorkstationAIVmware FusionAI15/7/202517/6/2026
VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on…
AplazadaCrítica (9.3)2.6%—Vmware EsxiAIVmware WorkstationAIVmware FusionAI15/7/202517/6/2026
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are…
AplazadaMedia (4.3)0.89%—Vmware EsxiAIVmware Vcenter ServerAI20/5/202517/6/2026
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.
AplazadaMedia (5.5)0.16%—Vmware EsxiAIVmware WorkstationAIVmware FusionAI20/5/202517/6/2026
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition.
AplazadaMedia (6.8)0.24%—Vmware EsxiAIVmware Vcenter ServerAIVmware ToolsAI20/5/202517/6/2026
VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools…
AnalizadaMedia (6)1.8%⚠ Explotación activaVmware EsxiVmware Cloud FoundationVmware FusionVmware Telco Cloud Infrastructure+24/3/202517/6/2026
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
AnalizadaAlta (8.2)1.0%⚠ Explotación activaVmware EsxiVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform4/3/20254/8/2026
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
AnalizadaAlta (8.2)1.6%⚠ Explotación activaVmware EsxiVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform+14/3/202517/6/2026
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
AnalizadaMedia (6.8)0.19%—Vmware Cloud FoundationVmware Esxi25/6/202417/6/2026
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.
AnalizadaAlta (7.2)27%⚠ Explotación activaVmware Cloud FoundationVmware Esxi25/6/202417/6/2026
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by…
ModificadaAlta (7.8)0.17%—Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion21/5/202417/6/2026
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in…
AnalizadaAlta (7.1)2.3%—Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion5/3/202417/6/2026
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
AnalizadaAlta (8.2)0.50%—Vmware Cloud FoundationVmware Esxi5/3/202417/6/2026
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
AnalizadaMedia (6.7)0.65%—Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion5/3/202417/6/2026
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained…
ModificadaMedia (6.7)3.5%—Vmware WorkstationVmware EsxiVmware Fusion5/3/202417/6/2026
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained…
AnalizadaAlta (7.5)64%⚠ Explotación activaNetapp Smi-s ProviderSuse Manager ServerSuse Linux Enterprise ServerVmware Esxi+125/4/202317/6/2026
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.