Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

104 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)2.6%⚠ Explotación activaVmware Vcenter Server30/7/202619/8/2026
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
AnalizadaCrítica (9.8)0.61%—Vmware Vcenter Server30/7/202625/8/2026
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
AplazadaMedia (4.3)0.89%—Vmware EsxiAIVmware Vcenter ServerAI20/5/202517/6/2026
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.
AplazadaMedia (6.8)0.24%—Vmware EsxiAIVmware Vcenter ServerAIVmware ToolsAI20/5/202517/6/2026
VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools…
AplazadaAlta (8.8)0.26%—Vmware Vcenter ServerAI20/5/202517/6/2026
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
AnalizadaCrítica (9.8)17%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server17/9/202417/6/2026
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
AnalizadaCrítica (9.8)55%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server17/9/202417/6/2026
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
AnalizadaMedia (5.3)0.71%—Vmware Cloud FoundationVmware Vcenter Server25/6/202417/6/2026
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
AnalizadaAlta (7.8)5.0%—Vmware Vcenter ServerVmware Cloud Foundation18/6/202417/6/2026
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
ModificadaCrítica (9.8)12%—Vmware Vcenter Server18/6/202417/6/2026
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
AnalizadaCrítica (9.8)22%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server18/6/202417/6/2026
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
AnalizadaMedia (4.9)0.99%—Vmware Cloud FoundationVmware Vcenter Server21/5/202417/6/2026
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
AnalizadaAlta (7.2)2.5%—Vmware Cloud FoundationVmware Vcenter Server21/5/202417/6/2026
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
ModificadaMedia (4.3)0.67%—Vmware Vcenter Server25/10/202317/6/2026
vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.
AnalizadaCrítica (9.8)99%⚠ Explotación activaVmware Vcenter Server25/10/202317/6/2026
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
ModificadaAlta (7.5)0.90%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and…
ModificadaCrítica (9.8)1.4%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
ModificadaCrítica (9.8)34%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
ModificadaCrítica (9.8)1.2%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.
ModificadaCrítica (9.8)1.8%—Vmware Vcenter Server22/6/202317/6/2026
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts…
ModificadaMedia (5.3)48%—Vmware Cloud FoundationVmware Vcenter Server13/12/202217/6/2026
The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header.
ModificadaMedia (5.5)0.13%—Vmware Vcenter ServerVmware Cloud Foundation13/12/202217/6/2026
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
ModificadaCrítica (9.1)33%—Vmware Vcenter Server7/10/202217/6/2026
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.
ModificadaAlta (7.5)1.0%—Vmware Cloud FoundationVmware Vcenter Server13/7/202217/6/2026
The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
ModificadaAlta (7.5)2.6%—Eclipse JettyDebian LinuxNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCI+47/7/202217/6/2026
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good…