Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloud Foundation MEDIUM 5.3
CVE-2022-22961

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess informa…

Fix: 5.0 / 9.0+
Fix from $1,600 2022-04-13
Identity Manager CRITICAL 9.8
CVE-2022-22955EPSS 8%

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious …

Fix: 9.0+
Fix from $2,300 2022-04-13
Identity Manager CRITICAL 9.8
CVE-2022-22956EPSS 51%

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious …

Fix: 9.0+
Fix from $2,300 2022-04-13
Identity Manager CRITICAL 9.8
CVE-2022-22954 KEVEPSS 100%

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious act…

Fix: after 8.2
Fix from $2,300 2022-04-11
Horizon HIGH 7.8
CVE-2022-22962

VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location d…

Fix: 2203+
Fix from $1,950 2022-04-11
Horizon HIGH 7.8
CVE-2022-22964

VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable confi…

Fix: 2203+
Fix from $1,950 2022-04-11
Photon Os MEDIUM 5.3
CVE-2021-22055

The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious …

Fix: 2022-02-16+
Fix from $1,600 2022-04-11
Spring Cloud Function CRITICAL 9.8
CVE-2022-22963 KEVEPSS 100%

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide …

Fix: after 3.2.2
Fix from $2,300 2022-04-01
Spring Framework CRITICAL 9.8
CVE-2022-22965 KEVEPSS 100%

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit …

Fix: 2.1.0 / 5.2.20+
Fix from $2,300 2022-04-01
Spring Framework MEDIUM 6.5
CVE-2022-22950EPSS 36%

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression t…

Fix: 5.2.20 / 5.3.17+
Fix from $1,600 2022-04-01
Spring Boot HIGH 7.8
CVE-2022-27772

spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springfram…

Fix: 2.2.11+
Fix from $1,950 2022-03-30
Cloud Foundation MEDIUM 6.5
CVE-2022-22948 KEVEPSS 13%

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative ac…

Fix: 3.11 / 4.4.1+
Fix from $1,600 2022-03-29
Carbon Black App Control CRITICAL 9.1
CVE-2022-22951EPSS 20%

VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command i…

Fix: 8.5.14 / 8.6.6+
Fix from $2,300 2022-03-23
Carbon Black App Control CRITICAL 9.1
CVE-2022-22952

VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload v…

Fix: 8.5.14 / 8.6.6+
Fix from $2,300 2022-03-23
Spring Cloud Gateway MEDIUM 5.5
CVE-2022-22946

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set …

Patch available
Fix from $1,600 2022-03-04
Spring Cloud Gateway CRITICAL 10.0
CVE-2022-22947 KEVEPSS 98%

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoi…

Fix: 3.0.7+
Fix from $2,300 2022-03-03
Tools MEDIUM 6.7
CVE-2022-22943

VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local adminis…

Fix: 12.0.0+
Fix from $1,600 2022-03-03
Workspace One Boxer MEDIUM 5.4
CVE-2022-22944

VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Wor…

Fix: 22.02+
Fix from $1,600 2022-03-02
Cloud Foundation HIGH 7.8
CVE-2022-22945

VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary comman…

Fix: 6.4.13+
Fix from $1,950 2022-02-16
Cloud Foundation HIGH 7.8
CVE-2021-22042

VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privile…

Fix: 4.4+
Fix from $1,950 2022-02-16
Fusion HIGH 7.5
CVE-2021-22043

VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with ac…

Fix: 4.4+
Fix from $1,950 2022-02-16
Cloud Foundation HIGH 7.5
CVE-2021-22050

ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to…

Fix: 3.11 / 4.4+
Fix from $1,950 2022-02-16
Cloud Foundation MEDIUM 6.7
CVE-2021-22040

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative p…

Fix: 3.11 / 4.4+
Fix from $1,600 2022-02-16
Cloud Foundation MEDIUM 6.7
CVE-2021-22041

VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative pri…

Fix: 3.11 / 4.4+
Fix from $1,600 2022-02-16
Workstation MEDIUM 6.5
CVE-2022-22938

VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Corta…

Fix: 5.5.3 / 16.2.2+
Fix from $1,600 2022-01-28
Cloud Foundation HIGH 7.8
CVE-2021-22045

VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contai…

Fix: 12.2.0 / 16.2.0+
Fix from $1,950 2022-01-04
Workspace One Access HIGH 8.8
CVE-2021-22057

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provi…

Patch available
Fix from $1,950 2021-12-20
Identity Manager HIGH 7.5
CVE-2021-22056

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor…

Fix: after 8.6
Fix from $1,950 2021-12-20
Workspace One Uem Console HIGH 7.5
CVE-2021-22054 KEVEPSS 97%

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 con…

Fix: 20.0.8.36 / 20.11.0.40+
Fix from $1,950 2021-12-17
Spring Advanced Message Queuing Protocol MEDIUM 6.5
CVE-2021-22095

In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object …

Fix: 2.2.19 / 2.3.11+
Fix from $1,600 2021-11-30