Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.73%—Vmware Cloud FoundationVmware FusionVmware Workstation PlayerVmware Workstation PRO+116/2/202217/6/2026
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
ModificadaAlta (7.7)0.83%—Vmware EsxiVmware Cloud FoundationVmware WorkstationVmware Workstation Player+120/10/202017/6/2026
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a…
ModificadaMedia (6.5)0.32%—Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO16/9/202017/6/2026
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerability due to an integer overflow issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to leak memory from TPView process…
ModificadaBaja (3.3)0.29%—Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO16/9/202017/6/2026
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability due to an out-of-bounds write issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to create a partial denial-of-service…
ModificadaMedia (6.1)0.30%—Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO16/9/202017/6/2026
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (JPEG2000 parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to…
ModificadaMedia (6.1)0.30%—Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO16/9/202017/6/2026
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service…
ModificadaMedia (6.1)0.30%—Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO16/9/202017/6/2026
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMF Parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak…
ModificadaAlta (7.2)14%—F5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+1213/4/201817/6/2026
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
ModificadaMedia (5.3)1.6%—Vmware Workstation PROVmware Workstation PlayerVmware Fusion15/3/201817/6/2026
VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled.
ModificadaMedia (5.5)1.2%—Vmware FusionVmware Fusion PROVmware Workstation PlayerVmware Workstation PRO+17/6/201717/6/2026
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have…
ModificadaAlta (8.8)0.43%—Vmware FusionVmware Fusion PROVmware Workstation PlayerVmware Workstation PRO+17/6/201717/6/2026
The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion…
ModificadaAlta (8.8)0.41%—Vmware Workstation PlayerVmware Workstation PROVmware EsxiVmware Fusion+17/6/201717/6/2026
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have…
ModificadaAlta (8.8)0.52%—Vmware Workstation PlayerVmware Workstation PROVmware EsxiVmware Fusion+17/6/201717/6/2026
VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Buffer Overflow in SVGA. This issue may allow a guest to execute code on the host.
ModificadaMedia (5.5)0.34%—Vmware Workstation PlayerVmware Workstation PRO7/6/201717/6/2026
VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
ModificadaMedia (4.7)0.29%—Vmware Workstation PlayerVmware Workstation PRO7/6/201717/6/2026
VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can be triggered only when the host has no graphics card or no graphics drivers are installed.
ModificadaAlta (8.8)0.39%—Vmware Workstation PlayerVmware Workstation PRO7/6/201717/6/2026
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where…
ModificadaMedia (6.5)5.0%—Vmware Workstation PlayerVmware Workstation PRO22/5/201717/6/2026
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial-of-service in a Windows host machine.
ModificadaAlta (7.8)5.4%—Vmware Workstation PlayerVmware Workstation PRO22/5/201717/6/2026
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.
ModificadaAlta (8.8)0.54%—Vmware FusionVmware Fusion PROVmware Workstation PlayerVmware Workstation PRO29/12/201617/6/2026
The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS)…
ModificadaAlta (7.8)0.34%—Vmware Workstation PlayerVmware Workstation PRO29/12/201617/6/2026
The installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse setup64.exe file in the installation directory.
ModificadaAlta (7.8)0.42%—Vmware Workstation PlayerVmware Workstation PRO29/12/201617/6/2026
Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)1.5%—Vmware Workstation PlayerVmware Workstation PRO29/12/201617/6/2026
tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memory corruption) via a JPEG 2000 image.
ModificadaAlta (7.8)1.5%—Vmware Workstation PlayerVmware Workstation PRO29/12/201617/6/2026
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memory corruption) via TrueType fonts embedded in EMFSPOOL.
ModificadaAlta (7.8)0.38%—Vmware Workstation PlayerVmware Workstation PRO29/12/201617/6/2026
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memory corruption) via an EMF file.
ModificadaAlta (7.8)0.52%—Vmware Workstation PlayerVmware Workstation PRO29/12/201617/6/2026
Multiple heap-based buffer overflows in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.