Vulnerability index

Browse CVEs

34 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Vcenter Server CRITICAL 9.8
CVE-2026-59310 KEV

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i…

No fix yet
Fix from $2,300 2026-07-30
Aria Operations HIGH 8.1
CVE-2026-22719 KEVEPSS 17%

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary comm…

Fix: 5.2.3 / 8.18.6+
Fix from $1,950 2026-02-25
Aria Operations HIGH 7.8
CVE-2025-41244 KEVEPSS 8%

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privilege…

Fix: 5.0.1 / 8.18.5+
Fix from $1,950 2025-09-29
Esxi HIGH 8.2
CVE-2025-22224 KEV

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with …

Fix: 17.6.3+
Fix from $1,950 2025-03-04
Esxi HIGH 8.2
CVE-2025-22225 KEV

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write…

Mitigation only
Fix from $1,950 2025-03-04
Esxi MEDIUM 6.0
CVE-2025-22226 KEV

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with adm…

Fix: 13.6.3 / 17.6.3+
Fix from $1,600 2025-03-04
Cloud Foundation CRITICAL 9.8
CVE-2024-38813 KEVEPSS 17%

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerabil…

Fix: 5.2+
Fix from $2,300 2024-09-17
Cloud Foundation CRITICAL 9.8
CVE-2024-38812 KEVEPSS 55%

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCen…

Fix: 5.2+
Fix from $2,300 2024-09-17
Cloud Foundation HIGH 7.2
CVE-2024-37085 KEVEPSS 26%

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access…

Fix: 5.2+
Fix from $1,950 2024-06-25
Cloud Foundation CRITICAL 9.8
CVE-2024-37079 KEVEPSS 22%

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter …

Fix: 5.2+
Fix from $2,300 2024-06-18
Vcenter Server CRITICAL 9.8
CVE-2023-34048 KEVEPSS 99%

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to v…

Fix: after 5.5
Fix from $2,300 2023-10-25
Aria Operations For Networks CRITICAL 9.8
CVE-2023-20887 KEVEPSS 98%

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks…

Fix: after 6.10.0
Fix from $2,300 2023-06-07
Esxi HIGH 7.5
CVE-2023-29552 KEVEPSS 66%

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacke…

Fix: 7.0+
Fix from $1,950 2023-04-25
Cloud Foundation HIGH 7.8
CVE-2022-22960 KEVEPSS 36%

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in sup…

Fix: 5.0 / 9.0+
Fix from $1,950 2022-04-13
Identity Manager CRITICAL 9.8
CVE-2022-22954 KEVEPSS 100%

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious act…

Fix: after 8.2
Fix from $2,300 2022-04-11
Spring Cloud Function CRITICAL 9.8
CVE-2022-22963 KEVEPSS 100%

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide …

Fix: after 3.2.2
Fix from $2,300 2022-04-01
Spring Framework CRITICAL 9.8
CVE-2022-22965 KEVEPSS 100%

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit …

Fix: 2.1.0 / 5.2.20+
Fix from $2,300 2022-04-01
Cloud Foundation MEDIUM 6.5
CVE-2022-22948 KEVEPSS 13%

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative ac…

Fix: 3.11 / 4.4.1+
Fix from $1,600 2022-03-29
Spring Cloud Gateway CRITICAL 10.0
CVE-2022-22947 KEVEPSS 98%

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoi…

Fix: 3.0.7+
Fix from $2,300 2022-03-03
Workspace One Uem Console HIGH 7.5
CVE-2021-22054 KEVEPSS 97%

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 con…

Fix: 20.0.8.36 / 20.11.0.40+
Fix from $1,950 2021-12-17
Vcenter Server MEDIUM 5.3
CVE-2021-22017 KEVEPSS 49%

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acce…

Patch available
Fix from $1,600 2021-09-23
Cloud Foundation CRITICAL 9.8
CVE-2021-22005 KEVEPSS 100%

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCe…

Fix: 5.0+
Fix from $2,300 2021-09-23
Vcenter Server CRITICAL 9.8
CVE-2021-21985 KEVEPSS 100%

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whi…

Fix: 3.10.2.1 / 4.2.1+
Fix from $2,300 2021-05-26
Cloud Foundation HIGH 7.5
CVE-2021-21975 KEVEPSS 78%

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the v…

Mitigation only
Fix from $1,950 2021-03-31
Cloud Foundation CRITICAL 9.8
CVE-2021-21972 KEVEPSS 100%

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 4…

Fix: 3.10.1.2 / 4.2+
Fix from $2,300 2021-02-24
Cloud Foundation MEDIUM 5.3
CVE-2021-21973 KEVEPSS 88%

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin…

Fix: 3.10.1.2 / 4.2+
Fix from $1,600 2021-02-24
Identity Manager CRITICAL 9.1
CVE-2020-4006 KEVEPSS 17%

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

Fix: after 8.2
Fix from $2,300 2020-11-23
Cloud Foundation CRITICAL 9.8
CVE-2020-3992 KEVEPSS 83%

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after…

Fix: 3.10.1.2 / 4.1.0.1+
Fix from $2,300 2020-10-20
Spring Cloud Config HIGH 7.5
CVE-2020-5410 KEVEPSS 96%

Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitra…

Fix: 2.1.9 / 2.2.3+
Fix from $1,950 2020-06-02
Vcenter Server CRITICAL 9.8
CVE-2020-3952 KEVEPSS 90%

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does no…

Mitigation only
Fix from $2,300 2020-04-10