Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1338▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8)0.42%—Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud PlatformVmware Vsphere8/6/202623/7/2026
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
AnalizadaMedia (5.4)0.32%—Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud PlatformVmware Vsphere8/6/202623/7/2026
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
ModificadaAlta (7.5)0.43%—IBM Storage Virtualize Plugin FOR Vsphere21/3/202517/6/2026
IBM Storage Virtualize vSphere Remote Plug-in 1.0 and 1.1 could allow a remote user to obtain sensitive credential information after deployment.
AplazadaAlta (8.5)0.44%—RancherAIVmware VsphereAI13/11/202417/6/2026
A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy clusters through the vSphere cloud provider. This issue leads to the vSphere CPI and CSI passwords being stored in a plaintext object inside…
ModificadaMedia (5.5)0.13%—Dell Replay Manager FOR VmwareDell Storage Integration Tools FOR VmwareDell Storage Vsphere Client Plugin16/8/202317/6/2026
Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to…
ModificadaCrítica (9.8)1.3%—Vsphere Selfuse Project Vsphere Selfuse14/12/202217/6/2026
vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaAlta (8.4)0.28%—Vmware FusionVmware WorkstationVmware Vsphere Esxi15/9/202117/6/2026
VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrative access to a virtual machine with a virtual NVMe…
ModificadaAlta (7.2)2.1%—Vmware Vsphere Replication11/2/202117/6/2026
vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication command injection vulnerability which may allow an authenticated admin user to perform a remote code execution.
ModificadaMedia (5.4)0.97%—Vmware EsxiVmware Vsphere EsxiVmware Vcenter Server18/9/201917/6/2026
VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session…
ModificadaAlta (8.8)5.6%—Linux KernelRedhat Enterprise LinuxCanonical Ubuntu LinuxNetapp A700s Firmware+83/6/201917/6/2026
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
ModificadaAlta (7.7)4.3%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+1025/4/201917/6/2026
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net…
ModificadaMedia (5.5)0.54%—Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+924/4/201917/6/2026
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial…
ModificadaMedia (4.7)0.34%—Linux KernelDebian LinuxNetapp Active IQ Unified Manager FOR Vmware VsphereNetapp HCI Management Node+622/4/201917/6/2026
A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target task to perform an execve() syscall with setuid execution before…
ModificadaMedia (6.5)1.8%—Linux KernelDebian LinuxRedhat Enterprise LinuxCanonical Ubuntu Linux+525/3/201917/6/2026
The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.
ModificadaMedia (6.7)1.0%—Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection26/11/201817/6/2026
'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute…
ModificadaMedia (6.5)0.83%—Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection26/11/201817/6/2026
Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked in the Avamar Java management client package. The private…
ModificadaMedia (6.1)1.8%—Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection26/11/201817/6/2026
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remote unauthenticated attacker could potentially exploit this…
ModificadaCrítica (9.8)9.9%—Dell EMC AvamarDell EMC Integrated Data Protection ApplianceVmware Vsphere Data Protection26/11/201817/6/2026
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain a Remote Code Execution vulnerability. A remote unauthenticated attacker could potentially exploit…
ModificadaAlta (8.8)0.68%—Jenkins Vsphere5/4/201817/6/2026
A cross-site request forgery vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java, ExposeGuestInfo.java, FolderVSphereCloudProperty.java, PowerOff.java, PowerOn.java,…
ModificadaMedia (6.3)0.69%—Jenkins Vsphere5/4/201817/6/2026
An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java, ExposeGuestInfo.java, FolderVSphereCloudProperty.java, PowerOff.java, PowerOn.java,…
ModificadaMedia (5.6)0.42%—Jenkins Vsphere5/4/201817/6/2026
A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.
ModificadaCrítica (9.8)8.6%—Vmware Vrealize AutomationVmware Vsphere Integrated Containers29/1/201817/6/2026
VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance.
ModificadaCrítica (9.8)0.84%—Vmware Vsphere Data Protection7/6/201717/6/2026
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
ModificadaCrítica (9.8)8.8%—Vmware Vsphere Data Protection7/6/201717/6/2026
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
ModificadaCrítica (9.8)1.2%—Netapp Virtual Storage Console FOR Vmware Vsphere7/2/201717/6/2026
NetApp Virtual Storage Console for VMware vSphere before 6.2.1 uses a non-unique certificate, which allows remote attackers to conduct man-in-the-middle attacks via unspecified vectors.