Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloud Foundation MEDIUM 6.5
CVE-2021-21983EPSS 69%

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with n…

No fix yet
Fix from $1,600 2021-03-31
Spring Boot CRITICAL 9.8
CVE-2021-26987

Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability…

Fix: 1.3.2 / 2.17.56+
Fix from $2,300 2021-03-15
View Planner CRITICAL 9.8
CVE-2021-21978EPSS 99%

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authoriza…

Fix: 4.6+
Fix from $2,300 2021-03-03
Spring Integration Zip MEDIUM 5.3
CVE-2021-22114

Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write vulnerability, that can be a…

Fix: 1.0.4+
Fix from $1,600 2021-03-01
Cloud Foundation HIGH 8.8
CVE-2021-21974EPSS 45%

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnera…

Fix: 3.10.1.2 / 4.2+
Fix from $1,950 2021-02-24
Cloud Foundation CRITICAL 9.8
CVE-2021-21972 KEVEPSS 100%

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 4…

Fix: 3.10.1.2 / 4.2+
Fix from $2,300 2021-02-24
Cloud Foundation MEDIUM 5.3
CVE-2021-21973 KEVEPSS 88%

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin…

Fix: 3.10.1.2 / 4.2+
Fix from $1,600 2021-02-24
Spring Security HIGH 8.8
CVE-2021-22112

Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the…

Fix: 5.2.9 / 5.3.8+
Fix from $1,950 2021-02-23
Spring Cloud Netflix Zuul MEDIUM 5.3
CVE-2021-22113

Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sen…

Fix: after 2.2.6
Fix from $1,600 2021-02-23
Vsphere Replication HIGH 7.2
CVE-2021-21976

vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication c…

Fix: 6.5.1.5 / 8.1.2.3+
Fix from $1,950 2021-02-11
Spring Cloud Data Flow HIGH 7.2
CVE-2020-5427

In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting t…

Fix: 2.5.4 / 2.6.5+
Fix from $1,950 2021-01-27
Spring Cloud Task MEDIUM 6.0
CVE-2020-5428

In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising certain lookup queries in the Tas…

Fix: after 2.2.4
Fix from $1,600 2021-01-27
Workstation MEDIUM 6.5
CVE-2020-3999

VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 an…

Fix: 11.5.7 / 15.5.7+
Fix from $1,600 2020-12-21
Sd Wan Orchestrator CRITICAL 9.8
CVE-2020-4001

The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default pas…

Fix: after 4.0.1
Fix from $2,300 2020-11-24
Sd Wan Orchestrator HIGH 8.8
CVE-2020-3985

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization levels leading to a privileg…

Fix: 3.4.4+
Fix from $1,950 2020-11-24
Sd Wan Orchestrator HIGH 8.8
CVE-2020-4000EPSS 43%

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversa…

Fix: 3.4.4 / 4.0.1+
Fix from $1,950 2020-11-24
Sd Wan Orchestrator HIGH 7.2
CVE-2020-4002

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An auth…

Fix: 3.4.4 / 4.0.1+
Fix from $1,950 2020-11-24
Sd Wan Orchestrator MEDIUM 6.5
CVE-2020-3984EPSS 22%

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An a…

Fix: 3.4.4+
Fix from $1,600 2020-11-24
Sd Wan Orchestrator MEDIUM 6.5
CVE-2020-4003

VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attack…

Fix: 3.4.4 / 4.0.1+
Fix from $1,600 2020-11-24
Identity Manager CRITICAL 9.1
CVE-2020-4006 KEVEPSS 17%

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

Fix: after 8.2
Fix from $2,300 2020-11-23
Fusion HIGH 8.2
CVE-2020-4004

VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusi…

Fix: 3.10.1.2 / 4.1.0.1+
Fix from $1,950 2020-11-20
Cloud Foundation HIGH 7.8
CVE-2020-4005

VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege-escalation vulnera…

Fix: 3.10.1.2 / 4.1.0.1+
Fix from $1,950 2020-11-20
Pivotal Scheduler CRITICAL 9.8
CVE-2020-5426

Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also…

Fix: 1.4.0+
Fix from $2,300 2020-11-11
Single Sign On For Tanzu HIGH 7.9
CVE-2020-5425

Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user imper…

Fix: 1.11.3 / 1.12.4+
Fix from $1,950 2020-10-31
Horizon Client MEDIUM 6.5
CVE-2020-3998

VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges o…

Fix: 5.5.0+
Fix from $1,600 2020-10-23
Horizon MEDIUM 5.4
CVE-2020-3997

VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may …

Fix: 7.10.3 / 7.13.0+
Fix from $1,600 2020-10-23
Velero MEDIUM 5.5
CVE-2020-3996

Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in information leakage to unauthorize…

Fix: 1.4.3 / 1.5.2+
Fix from $1,600 2020-10-22
Esxi MEDIUM 5.3
CVE-2020-3995

In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the…

Fix: 3.9 / 11.1.0+
Fix from $1,600 2020-10-20
Cloud Foundation CRITICAL 9.8
CVE-2020-3992 KEVEPSS 83%

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after…

Fix: 3.10.1.2 / 4.1.0.1+
Fix from $2,300 2020-10-20
Esxi HIGH 7.7
CVE-2020-3982

VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x …

Fix: 3.10.1 / 4.1+
Fix from $1,950 2020-10-20