Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vcenter Server CRITICAL 9.8
CVE-2021-22049

The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A maliciou…

Patch available
Fix from $2,300 2021-11-24
Cloud Foundation HIGH 7.5
CVE-2021-21980

The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on …

Patch available
Fix from $1,950 2021-11-24
Spring Cloud Netflix HIGH 8.8
CVE-2021-22053EPSS 13%

Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within th…

Fix: 2.2.10+
Fix from $1,950 2021-11-19
Cloud Foundation HIGH 8.8
CVE-2021-22048EPSS 10%

The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious…

Fix: after 4.1.0.1
Fix from $1,950 2021-11-10
Spring Cloud Gateway MEDIUM 6.5
CVE-2021-22051

Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. User…

Fix: 2.2.10 / 3.0.5+
Fix from $1,600 2021-11-08
Installbuilder HIGH 8.8
CVE-2021-22038

On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so i…

Fix: 21.6.0+
Fix from $1,950 2021-10-29
Installbuilder HIGH 7.8
CVE-2021-22037

Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is …

Fix: 21.6.0+
Fix from $1,950 2021-10-29
Spring Advanced Message Queuing Protocol MEDIUM 6.5
CVE-2021-22097

In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a me…

Fix: after 2.3.10
Fix from $1,600 2021-10-28
Spring Cloud Openfeign HIGH 7.5
CVE-2021-22044

In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapp…

Fix: after 3.0.4
Fix from $1,950 2021-10-28
Spring Data Rest MEDIUM 5.3
CVE-2021-22047

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a …

Fix: after 3.5.5
Fix from $1,600 2021-10-28
Vrealize Operations Tenant HIGH 7.5
CVE-2021-22034

Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability.

Fix: 8.6+
Fix from $1,950 2021-10-21
Vrealize Automation MEDIUM 6.5
CVE-2021-22036

VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able…

Fix: 8.6+
Fix from $1,600 2021-10-13
Cloud Foundation HIGH 7.5
CVE-2021-22019

The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vC…

Fix: 3.10.2.2 / 4.3+
Fix from $1,950 2021-09-23
Cloud Foundation MEDIUM 6.5
CVE-2021-22018

The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network a…

Fix: 4.3.1+
Fix from $1,600 2021-09-23
Cloud Foundation MEDIUM 6.1
CVE-2021-22016

The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to…

Fix: 5.0+
Fix from $1,600 2021-09-23
Cloud Foundation MEDIUM 5.5
CVE-2021-22020

The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker t…

Fix: 3.10.2.2 / 4.3+
Fix from $1,600 2021-09-23
Vcenter Server MEDIUM 5.3
CVE-2021-22017 KEVEPSS 49%

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acce…

Patch available
Fix from $1,600 2021-09-23
Cloud Foundation HIGH 7.8
CVE-2021-22015

The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticate…

Fix: 5.0+
Fix from $1,950 2021-09-23
Cloud Foundation HIGH 7.5
CVE-2021-22012

The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with networ…

Fix: 5.0+
Fix from $1,950 2021-09-23
Cloud Foundation HIGH 7.5
CVE-2021-22013

The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor …

Fix: 5.0+
Fix from $1,950 2021-09-23
Cloud Foundation HIGH 7.2
CVE-2021-22014

The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAM…

Fix: 5.0+
Fix from $1,950 2021-09-23
Cloud Foundation CRITICAL 9.8
CVE-2021-22005 KEVEPSS 100%

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCe…

Fix: 5.0+
Fix from $2,300 2021-09-23
Cloud Foundation HIGH 7.5
CVE-2021-22006EPSS 6%

The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access t…

Fix: 5.0+
Fix from $1,950 2021-09-23
Cloud Foundation HIGH 7.5
CVE-2021-22008

The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 …

Fix: 5.0+
Fix from $1,950 2021-09-23
Cloud Foundation HIGH 7.5
CVE-2021-22009

The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 4…

Fix: 5.0+
Fix from $1,950 2021-09-23
Cloud Foundation HIGH 7.5
CVE-2021-22010

The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server ma…

Fix: 5.0+
Fix from $1,950 2021-09-23
Cloud Foundation MEDIUM 6.5
CVE-2021-21993

The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library.…

Fix: 5.0+
Fix from $1,600 2021-09-23
Cloud Foundation MEDIUM 5.5
CVE-2021-22007

The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative priv…

Fix: 5.0+
Fix from $1,600 2021-09-23
Cloud Foundation MEDIUM 5.3
CVE-2021-22011

vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to por…

Fix: 5.0+
Fix from $1,600 2021-09-23
Cloud Foundation HIGH 7.8
CVE-2021-21991

The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administr…

Fix: 3.10.2.2 / 4.3+
Fix from $1,950 2021-09-22