Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloud Foundation MEDIUM 6.5
CVE-2021-21992

The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user acce…

Fix: 3.10.2.2 / 4.3+
Fix from $1,600 2021-09-22
Fusion HIGH 8.4
CVE-2020-3960

VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) …

Fix: 11.5.5 / 15.5.5+
Fix from $1,950 2021-09-15
Identity Manager CRITICAL 9.8
CVE-2021-22002

VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a …

Patch available
Fix from $2,300 2021-08-31
Identity Manager HIGH 7.5
CVE-2021-22003

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to po…

Patch available
Fix from $1,950 2021-08-31
Workspace One Uem Console HIGH 7.5
CVE-2021-22029

VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause…

Fix: 20.1.0.33 / 20.5.0.51+
Fix from $1,950 2021-08-31
Cloud Foundation MEDIUM 5.4
CVE-2021-22021

VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker…

Fix: 4.3 / 8.4+
Fix from $1,600 2021-08-30
Cloud Foundation HIGH 7.5
CVE-2021-22024

The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with net…

Fix: 8.5.0+
Fix from $1,950 2021-08-30
Cloud Foundation HIGH 7.5
CVE-2021-22025

The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unaut…

Fix: 8.5.0+
Fix from $1,950 2021-08-30
Cloud Foundation HIGH 7.5
CVE-2021-22026

The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit…

Fix: 8.5.0+
Fix from $1,950 2021-08-30
Cloud Foundation HIGH 7.5
CVE-2021-22027

The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit…

Fix: 8.5.0+
Fix from $1,950 2021-08-30
Cloud Foundation HIGH 7.2
CVE-2021-22023

The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to v…

Fix: 8.5.0+
Fix from $1,950 2021-08-30
Cloud Foundation CRITICAL 9.8
CVE-2021-21994

SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on E…

Fix: 3.10.2 / 4.3+
Fix from $2,300 2021-07-13
Thinapp HIGH 7.8
CVE-2021-22000

VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administ…

Fix: 5.2.10+
Fix from $1,950 2021-07-13
Cloud Foundation HIGH 7.5
CVE-2021-21995

OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 …

Fix: 3.10.2 / 4.3+
Fix from $1,950 2021-07-13
Spring Security HIGH 7.5
CVE-2021-22119EPSS 6%

Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-S…

Fix: 5.2.11 / 5.3.10+
Fix from $1,950 2021-06-29
Rabbitmq MEDIUM 5.4
CVE-2021-32718

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the…

Fix: 3.8.17+
Fix from $1,600 2021-06-28
Carbon Black App Control CRITICAL 9.8
CVE-2021-21998EPSS 11%

VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network acc…

Fix: 8.5.8 / 8.6.2+
Fix from $2,300 2021-06-23
App Volumes HIGH 7.8
CVE-2021-21999

VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.1…

Fix: 2.18.10 / 11.2.6+
Fix from $1,950 2021-06-23
Tools MEDIUM 5.5
CVE-2021-21997

VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user …

Fix: 11.3.0+
Fix from $1,600 2021-06-18
Rabbitmq HIGH 7.5
CVE-2021-22116

RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection e…

Fix: 3.8.16+
Fix from $1,950 2021-06-08
Spring Framework HIGH 7.8
CVE-2021-22118

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation:…

Fix: 5.2.15 / 5.3.7+
Fix from $1,950 2021-05-27
Vcenter Server CRITICAL 9.8
CVE-2021-21985 KEVEPSS 100%

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whi…

Fix: 3.10.2.1 / 4.2.1+
Fix from $2,300 2021-05-26
Vcenter Server CRITICAL 9.8
CVE-2021-21986EPSS 13%

The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Li…

Fix: 3.10.2.1 / 4.2.1+
Fix from $2,300 2021-05-26
Workstation MEDIUM 6.5
CVE-2021-21987

VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado…

Fix: 5.5.2 / 16.1.2+
Fix from $1,600 2021-05-24
Workstation MEDIUM 6.5
CVE-2021-21988

VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado…

Fix: 5.5.2 / 16.1.2+
Fix from $1,600 2021-05-24
Workstation MEDIUM 6.5
CVE-2021-21989

VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado…

Fix: 5.5.2 / 16.1.2+
Fix from $1,600 2021-05-24
Workspace One Unified Endpoint Management MEDIUM 6.1
CVE-2021-21990

VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 2…

Fix: 19.12.0.24 / 20.1.0.32+
Fix from $1,600 2021-05-11
Vrealize Business For Cloud CRITICAL 9.8
CVE-2021-21984

VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious ac…

Fix: 7.6.0+
Fix from $2,300 2021-05-07
Carbon Black Cloud Workload CRITICAL 9.1
CVE-2021-21982

VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network …

Fix: after 1.0.1
Fix from $2,300 2021-04-01
Cloud Foundation HIGH 7.5
CVE-2021-21975 KEVEPSS 78%

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the v…

Mitigation only
Fix from $1,950 2021-03-31