Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.18% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system. | |
| Modificada | Alta (7.2) | 1.0% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system. | |
| Modificada | Alta (8.8) | 0.65% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation. | |
| Modificada | Alta (8.8) | 0.40% | — | Vmware Vrealize Operations | 1/2/2023 | 17/6/2026 | VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user. | |
| Modificada | Media (4.9) | 0.82% | — | Vmware Vrealize Operations | 16/12/2022 | 17/6/2026 | vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4. | |
| Modificada | Alta (7.2) | 0.99% | — | Vmware Vrealize Operations | 16/12/2022 | 17/6/2026 | vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2. | |
| Modificada | Media (4.9) | 0.64% | — | Vmware Vrealize Operations | 11/10/2022 | 17/6/2026 | VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with administrative privileges may be able to read arbitrary files containing sensitive data. | |
| Modificada | Alta (7.5) | 0.81% | — | Vmware Vrealize Operations | 10/8/2022 | 17/6/2026 | VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges. | |
| Modificada | Media (4.3) | 0.63% | — | Vmware Vrealize Operations | 10/8/2022 | 17/6/2026 | VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure. | |
| Modificada | Alta (8.8) | 1.6% | — | Vmware Vrealize Operations | 10/8/2022 | 17/6/2026 | VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution. | |
| Modificada | Alta (7.2) | 0.64% | — | Vmware Vrealize Operations | 10/8/2022 | 17/6/2026 | VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root. | |
| Modificada | Alta (7.5) | 1.0% | — | Vmware Vrealize Operations Tenant | 21/10/2021 | 17/6/2026 | Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability. | |
| Modificada | Baja (2.7) | 0.61% | — | Vmware Cloud FoundationVmware Vrealize OperationsVmware Vrealize Suite Lifecycle Manager | 13/10/2021 | 17/6/2026 | Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability. | |
| Modificada | Alta (7.5) | 1.2% | — | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 30/8/2021 | 17/6/2026 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information disclosure. | |
| Modificada | Alta (7.5) | 1.1% | — | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 30/8/2021 | 17/6/2026 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information disclosure. | |
| Modificada | Alta (7.5) | 0.81% | — | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 30/8/2021 | 17/6/2026 | The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to existing vROps cluster. | |
| Modificada | Alta (7.5) | 1.0% | — | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 30/8/2021 | 17/6/2026 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information disclosure. | |
| Modificada | Alta (7.2) | 1.00% | — | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 30/8/2021 | 17/6/2026 | The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account takeover. | |
| Modificada | Media (4.9) | 1.1% | — | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 30/8/2021 | 17/6/2026 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure. | |
| Modificada | Media (6.5) | 69% | — | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 31/3/2021 | 12/8/2026 | Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system. | |
| Analizada | Alta (7.5) | 78% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 31/3/2021 | 2/10/2026 | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials. | |
| Modificada | Alta (7.5) | 1.4% | — | Vmware Vrealize Operations | 19/2/2020 | 17/6/2026 | vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize… | |
| Modificada | Alta (8.6) | 1.5% | — | Vmware Vrealize Operations | 19/2/2020 | 17/6/2026 | vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to bypass Adapter… | |
| Modificada | Crítica (9.8) | 2.3% | — | Vmware Vrealize Operations | 19/2/2020 | 17/6/2026 | vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize… | |
| Modificada | Media (6.7) | 0.33% | — | Vmware Vrealize Operations | 18/12/2018 | 17/6/2026 | vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper permissions of support scripts. Admin user of the vROps application with shell access may exploit this issue to elevate the privileges to root… |