Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-59310 KEV
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i…
Vcenter Server
No fix yet
HIGH 7.5
CVE-2026-22750
When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored an…
Spring Cloud Gateway
Mitigation only
HIGH 8.2
CVE-2025-22225 KEV
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write…
Esxi
Mitigation only
HIGH 7.5
CVE-2024-22233
In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-servic…
Spring Framework
Mitigation only
HIGH 7.8
CVE-2022-22942
The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processe…
Photon Os
Mitigation only
MEDIUM 5.3
CVE-2023-34038
VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relat…
Horizon Client
Mitigation only
MEDIUM 5.3
CVE-2023-34037
VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requ…
Horizon Client
Mitigation only
HIGH 8.8
CVE-2023-20872
VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
Fusion
Mitigation only
MEDIUM 6.5
CVE-2023-20866
In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to thos…
Spring Session
Mitigation only
HIGH 7.2
CVE-2022-31700
VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of t…
Access
Mitigation only
MEDIUM 5.3
CVE-2022-31701
VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be…
Access
Mitigation only
MEDIUM 5.5
CVE-2022-31697
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to …
Vcenter Server
Mitigation only
MEDIUM 5.3
CVE-2022-31698EPSS 48%
The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vC…
Cloud Foundation
Mitigation only
MEDIUM 6.7
CVE-2009-1142
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wr…
Open Vm Tools
Mitigation only
CRITICAL 9.9
CVE-2022-38652
A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authent…
Hyperic Agent
Mitigation only
CRITICAL 9.8
CVE-2022-38651
A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some…
Hyperic Server
Mitigation only
CRITICAL 10.0
CVE-2022-38650
A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a m…
Hyperic Server
Mitigation only
MEDIUM 6.5
CVE-2022-22953
VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be ab…
Vmware Hcx
Mitigation only
CRITICAL 9.8
CVE-2022-22972EPSS 56%
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A …
Identity Manager
Mitigation only
HIGH 7.8
CVE-2022-22973
VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privi…
Identity Manager
Mitigation only
HIGH 7.5
CVE-2021-21975 KEVEPSS 78%
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the v…
Cloud Foundation
Mitigation only
MEDIUM 6.5
CVE-2021-21983EPSS 69%
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with n…
Cloud Foundation
No fix yet
CRITICAL 9.8
CVE-2020-3952 KEVEPSS 90%
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does no…
Vcenter Server
Mitigation only
HIGH 8.6
CVE-2019-5098
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can ca…
Workstation
No fix yet
MEDIUM 5.9
CVE-2019-5537
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of…
Vcenter Server
Mitigation only
MEDIUM 5.9
CVE-2019-5538
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of…
Vcenter Server
Mitigation only
MEDIUM 5.4
CVE-2019-5531
VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter …
Esxi
Mitigation only
HIGH 7.7
CVE-2019-5532
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to t…
Vcenter Server
No fix yet
HIGH 7.7
CVE-2019-5534
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Vi…
Vcenter Server
No fix yet
HIGH 8.1
CVE-2018-1256
Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO s…
Spring Cloud Sso Connector
Mitigation only