Vulnerability index

Browse CVEs

34 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-59310 KEV VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i… Vcenter Server No fix yet Fix from $2,3002026-07-30 HIGH 8.1 CVE-2026-22719 KEVEPSS 17% VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary comm… Aria Operations 5.2.3 / 8.18.6+ Fix from $1,9502026-02-25 HIGH 7.8 CVE-2025-41244 KEVEPSS 8% VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privilege… Aria Operations 5.0.1 / 8.18.5+ Fix from $1,9502025-09-29 HIGH 8.2 CVE-2025-22224 KEV VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with … Esxi 17.6.3+ Fix from $1,9502025-03-04 HIGH 8.2 CVE-2025-22225 KEV VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write… Esxi Mitigation only Fix from $1,9502025-03-04 MEDIUM 6.0 CVE-2025-22226 KEV VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with adm… Esxi 13.6.3 / 17.6.3+ Fix from $1,6002025-03-04 CRITICAL 9.8 CVE-2024-38813 KEVEPSS 17% The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerabil… Cloud Foundation 5.2+ Fix from $2,3002024-09-17 CRITICAL 9.8 CVE-2024-38812 KEVEPSS 55% The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCen… Cloud Foundation 5.2+ Fix from $2,3002024-09-17 HIGH 7.2 CVE-2024-37085 KEVEPSS 26% VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access… Cloud Foundation 5.2+ Fix from $1,9502024-06-25 CRITICAL 9.8 CVE-2024-37079 KEVEPSS 22% vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter … Cloud Foundation 5.2+ Fix from $2,3002024-06-18 CRITICAL 9.8 CVE-2023-34048 KEVEPSS 99% vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to v… Vcenter Server after 5.5 Fix from $2,3002023-10-25 CRITICAL 9.8 CVE-2023-20887 KEVEPSS 98% Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks… Aria Operations For Networks after 6.10.0 Fix from $2,3002023-06-07 HIGH 7.5 CVE-2023-29552 KEVEPSS 66% The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacke… Esxi 7.0+ Fix from $1,9502023-04-25 HIGH 7.8 CVE-2022-22960 KEVEPSS 36% VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in sup… Cloud Foundation 5.0 / 9.0+ Fix from $1,9502022-04-13 CRITICAL 9.8 CVE-2022-22954 KEVEPSS 100% VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious act… Identity Manager after 8.2 Fix from $2,3002022-04-11 CRITICAL 9.8 CVE-2022-22963 KEVEPSS 100% In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide … Spring Cloud Function after 3.2.2 Fix from $2,3002022-04-01 CRITICAL 9.8 CVE-2022-22965 KEVEPSS 100% A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit … Spring Framework 2.1.0 / 5.2.20+ Fix from $2,3002022-04-01 MEDIUM 6.5 CVE-2022-22948 KEVEPSS 13% The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative ac… Cloud Foundation 3.11 / 4.4.1+ Fix from $1,6002022-03-29 CRITICAL 10.0 CVE-2022-22947 KEVEPSS 98% In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoi… Spring Cloud Gateway 3.0.7+ Fix from $2,3002022-03-03 HIGH 7.5 CVE-2021-22054 KEVEPSS 97% VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 con… Workspace One Uem Console 20.0.8.36 / 20.11.0.40+ Fix from $1,9502021-12-17 MEDIUM 5.3 CVE-2021-22017 KEVEPSS 49% Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acce… Vcenter Server Patch available Fix from $1,6002021-09-23 CRITICAL 9.8 CVE-2021-22005 KEVEPSS 100% The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCe… Cloud Foundation 5.0+ Fix from $2,3002021-09-23 CRITICAL 9.8 CVE-2021-21985 KEVEPSS 100% The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whi… Vcenter Server 3.10.2.1 / 4.2.1+ Fix from $2,3002021-05-26 HIGH 7.5 CVE-2021-21975 KEVEPSS 78% Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the v… Cloud Foundation Mitigation only Fix from $1,9502021-03-31 CRITICAL 9.8 CVE-2021-21972 KEVEPSS 100% The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 4… Cloud Foundation 3.10.1.2 / 4.2+ Fix from $2,3002021-02-24 MEDIUM 5.3 CVE-2021-21973 KEVEPSS 88% The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin… Cloud Foundation 3.10.1.2 / 4.2+ Fix from $1,6002021-02-24 CRITICAL 9.1 CVE-2020-4006 KEVEPSS 17% VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. Identity Manager after 8.2 Fix from $2,3002020-11-23 CRITICAL 9.8 CVE-2020-3992 KEVEPSS 83% OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after… Cloud Foundation 3.10.1.2 / 4.1.0.1+ Fix from $2,3002020-10-20 HIGH 7.5 CVE-2020-5410 KEVEPSS 96% Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitra… Spring Cloud Config 2.1.9 / 2.2.3+ Fix from $1,9502020-06-02 CRITICAL 9.8 CVE-2020-3952 KEVEPSS 90% Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does no… Vcenter Server Mitigation only Fix from $2,3002020-04-10