Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 2.6% | ⚠ Explotación activa | Vmware Vcenter Server | 30/7/2026 | 19/8/2026 | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. | |
| Analizada | Crítica (9.8) | 0.61% | — | Vmware Vcenter Server | 30/7/2026 | 25/8/2026 | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system. | |
| Aplazada | Media (4.3) | 0.89% | — | Vmware EsxiAIVmware Vcenter ServerAI | 20/5/2025 | 17/6/2026 | VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites. | |
| Aplazada | Media (6.8) | 0.24% | — | Vmware EsxiAIVmware Vcenter ServerAIVmware ToolsAI | 20/5/2025 | 17/6/2026 | VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools… | |
| Aplazada | Alta (8.8) | 0.26% | — | Vmware Vcenter ServerAI | 20/5/2025 | 17/6/2026 | The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server. | |
| Analizada | Crítica (9.8) | 17% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vcenter Server | 17/9/2024 | 17/6/2026 | The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet. | |
| Analizada | Crítica (9.8) | 55% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vcenter Server | 17/9/2024 | 17/6/2026 | The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | |
| Analizada | Media (5.3) | 0.71% | — | Vmware Cloud FoundationVmware Vcenter Server | 25/6/2024 | 17/6/2026 | The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition. | |
| Analizada | Alta (7.8) | 5.0% | — | Vmware Vcenter ServerVmware Cloud Foundation | 18/6/2024 | 17/6/2026 | The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance. | |
| Modificada | Crítica (9.8) | 12% | — | Vmware Vcenter Server | 18/6/2024 | 17/6/2026 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | |
| Analizada | Crítica (9.8) | 22% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vcenter Server | 18/6/2024 | 17/6/2026 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | |
| Analizada | Media (4.9) | 0.99% | — | Vmware Cloud FoundationVmware Vcenter Server | 21/5/2024 | 17/6/2026 | The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data. | |
| Analizada | Alta (7.2) | 2.5% | — | Vmware Cloud FoundationVmware Vcenter Server | 21/5/2024 | 17/6/2026 | The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system. | |
| Modificada | Media (4.3) | 0.67% | — | Vmware Vcenter Server | 25/10/2023 | 17/6/2026 | vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Vmware Vcenter Server | 25/10/2023 | 17/6/2026 | vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution. | |
| Modificada | Alta (7.5) | 0.90% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and… | |
| Modificada | Crítica (9.8) | 1.4% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication. | |
| Modificada | Crítica (9.8) | 34% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption. | |
| Modificada | Crítica (9.8) | 1.2% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server. | |
| Modificada | Crítica (9.8) | 1.8% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts… | |
| Modificada | Media (5.3) | 48% | — | Vmware Cloud FoundationVmware Vcenter Server | 13/12/2022 | 17/6/2026 | The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header. | |
| Modificada | Media (5.5) | 0.13% | — | Vmware Vcenter ServerVmware Cloud Foundation | 13/12/2022 | 17/6/2026 | The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation. | |
| Modificada | Crítica (9.1) | 33% | — | Vmware Vcenter Server | 7/10/2022 | 17/6/2026 | The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server. | |
| Modificada | Alta (7.5) | 1.0% | — | Vmware Cloud FoundationVmware Vcenter Server | 13/7/2022 | 17/6/2026 | The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service. | |
| Modificada | Alta (7.5) | 2.6% | — | Eclipse JettyDebian LinuxNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCI+4 | 7/7/2022 | 17/6/2026 | In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good… |