Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-59310 KEV
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i…
Vcenter Server
No fix yet
HIGH 8.1
CVE-2026-22719 KEVEPSS 17%
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary comm…
Aria Operations
5.2.3 / 8.18.6+
HIGH 7.8
CVE-2025-41244 KEVEPSS 8%
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privilege…
Aria Operations
5.0.1 / 8.18.5+
HIGH 8.2
CVE-2025-22224 KEV
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with …
Esxi
17.6.3+
HIGH 8.2
CVE-2025-22225 KEV
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write…
Esxi
Mitigation only
MEDIUM 6.0
CVE-2025-22226 KEV
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with adm…
Esxi
13.6.3 / 17.6.3+
CRITICAL 9.8
CVE-2024-38813 KEVEPSS 17%
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerabil…
Cloud Foundation
5.2+
CRITICAL 9.8
CVE-2024-38812 KEVEPSS 55%
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCen…
Cloud Foundation
5.2+
HIGH 7.2
CVE-2024-37085 KEVEPSS 26%
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access…
Cloud Foundation
5.2+
CRITICAL 9.8
CVE-2024-37079 KEVEPSS 22%
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter …
Cloud Foundation
5.2+
CRITICAL 9.8
CVE-2023-34048 KEVEPSS 99%
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to v…
Vcenter Server
after 5.5
CRITICAL 9.8
CVE-2023-20887 KEVEPSS 98%
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks…
Aria Operations For Networks
after 6.10.0
HIGH 7.5
CVE-2023-29552 KEVEPSS 66%
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacke…
Esxi
7.0+
HIGH 7.8
CVE-2022-22960 KEVEPSS 36%
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in sup…
Cloud Foundation
5.0 / 9.0+
CRITICAL 9.8
CVE-2022-22954 KEVEPSS 100%
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious act…
Identity Manager
after 8.2
CRITICAL 9.8
CVE-2022-22963 KEVEPSS 100%
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide …
Spring Cloud Function
after 3.2.2
CRITICAL 9.8
CVE-2022-22965 KEVEPSS 100%
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit …
Spring Framework
2.1.0 / 5.2.20+
MEDIUM 6.5
CVE-2022-22948 KEVEPSS 13%
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative ac…
Cloud Foundation
3.11 / 4.4.1+
CRITICAL 10.0
CVE-2022-22947 KEVEPSS 98%
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoi…
Spring Cloud Gateway
3.0.7+
HIGH 7.5
CVE-2021-22054 KEVEPSS 97%
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 con…
Workspace One Uem Console
20.0.8.36 / 20.11.0.40+
MEDIUM 5.3
CVE-2021-22017 KEVEPSS 49%
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acce…
Vcenter Server
Patch available
CRITICAL 9.8
CVE-2021-22005 KEVEPSS 100%
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCe…
Cloud Foundation
5.0+
CRITICAL 9.8
CVE-2021-21985 KEVEPSS 100%
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whi…
Vcenter Server
3.10.2.1 / 4.2.1+
HIGH 7.5
CVE-2021-21975 KEVEPSS 78%
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the v…
Cloud Foundation
Mitigation only
CRITICAL 9.8
CVE-2021-21972 KEVEPSS 100%
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 4…
Cloud Foundation
3.10.1.2 / 4.2+
MEDIUM 5.3
CVE-2021-21973 KEVEPSS 88%
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin…
Cloud Foundation
3.10.1.2 / 4.2+
CRITICAL 9.1
CVE-2020-4006 KEVEPSS 17%
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
Identity Manager
after 8.2
CRITICAL 9.8
CVE-2020-3992 KEVEPSS 83%
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after…
Cloud Foundation
3.10.1.2 / 4.1.0.1+
HIGH 7.5
CVE-2020-5410 KEVEPSS 96%
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitra…
Spring Cloud Config
2.1.9 / 2.2.3+
CRITICAL 9.8
CVE-2020-3952 KEVEPSS 90%
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does no…
Vcenter Server
Mitigation only