Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Spring Framework MEDIUM 6.5
CVE-2018-1257

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP o…

Fix: 4.3.17 / 5.0.6+
Fix from $1,600 2018-05-11
Spring Cloud Sso Connector HIGH 8.1
CVE-2018-1256

Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO s…

Mitigation only
Fix from $1,950 2018-05-07
Xenon HIGH 7.5
CVE-2017-4952

VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authenticat…

Fix: after 1.5.3
Fix from $1,950 2018-05-02
Horizon Daas HIGH 8.8
CVE-2018-6960

VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication.…

Fix: 8.0.0+
Fix from $1,950 2018-04-20
Spring Data Rest HIGH 7.5
CVE-2018-1274

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by u…

Fix: 1.13.11 / 2.0.6+
Fix from $1,950 2018-04-18
Vrealize Automation CRITICAL 9.8
CVE-2018-6959

VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the h…

Fix: 7.4.0+
Fix from $2,300 2018-04-13
Vrealize Automation MEDIUM 6.1
CVE-2018-6958

VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitati…

Fix: 7.3.1+
Fix from $1,600 2018-04-13
Spring Data Rest CRITICAL 9.8
CVE-2018-1273 KEVEPSS 96%

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused …

Fix: after 3.0.5
Fix from $2,300 2018-04-11
Spring Framework CRITICAL 9.8
CVE-2018-1275EPSS 58%

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP ove…

Fix: 4.3.16 / 5.0.5+
Fix from $2,300 2018-04-11
Spring Framework CRITICAL 9.8
CVE-2018-1270EPSS 77%

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP ove…

Fix: 4.3.16 / 5.0.5+
Fix from $2,300 2018-04-06
Spring Framework HIGH 7.5
CVE-2018-1272

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multip…

Fix: 4.3.15 / 5.0.5+
Fix from $1,950 2018-04-06
Spring Framework MEDIUM 5.9
CVE-2018-1271EPSS 35%

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring…

Fix: 4.3.15 / 5.0.5+
Fix from $1,600 2018-04-06
Pivotal Software Mysql CRITICAL 10.0
CVE-2016-0898

MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup c…

Mitigation only
Fix from $2,300 2018-03-29
Spring Boot MEDIUM 5.9
CVE-2018-1196

Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script includ…

Fix: after 1.5.9
Fix from $1,600 2018-03-19
Spring Framework MEDIUM 5.3
CVE-2018-1199

Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x b…

Fix: 4.1.5 / 4.2.4+
Fix from $1,600 2018-03-16
Workstation Pro MEDIUM 5.3
CVE-2018-6957

VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggere…

Fix: 14.1.1+
Fix from $1,600 2018-03-15
Vrealize Automation CRITICAL 9.8
CVE-2017-4947EPSS 9%

VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Succes…

Fix: 1.3.0+
Fix from $2,300 2018-01-29
Airwatch HIGH 8.8
CVE-2017-4951

VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalo…

Fix: 9.1.5 / 9.2.2+
Fix from $1,950 2018-01-29
Fusion HIGH 7.0
CVE-2017-4949

VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may allow a guest to…

Fix: 8.5.10 / 10.1.1+
Fix from $1,950 2018-01-11
Fusion HIGH 7.0
CVE-2017-4950

VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an ou…

Fix: 8.5.10 / 10.1.1+
Fix from $1,950 2018-01-11
Vrealize Operations For Horizon HIGH 7.8
CVE-2017-4946

The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could r…

Fix: 6.5.1+
Fix from $1,950 2018-01-05
Workstation HIGH 7.1
CVE-2017-4948

VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll…

Fix: 4.7+
Fix from $1,950 2018-01-05
Workstation MEDIUM 5.5
CVE-2017-4945

VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via…

Patch available
Fix from $1,600 2018-01-05
Spring Boot CRITICAL 9.8
CVE-2017-8046EPSS 74%

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spr…

Fix: 1.5.9 / 2.6.9+
Fix from $2,300 2018-01-04
Workstation Pro HIGH 8.8
CVE-2017-4933

VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could all…

Fix: 8.5.9 / 12.5.8+
Fix from $1,950 2017-12-20
Fusion HIGH 8.8
CVE-2017-4941

VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vu…

Fix: 8.5.9 / 12.5.8+
Fix from $1,950 2017-12-20
Vcenter Server HIGH 7.8
CVE-2017-4943

VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful …

Patch available
Fix from $1,950 2017-12-20
Esxi MEDIUM 6.1
CVE-2017-4940

The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a…

Mitigation only
Fix from $1,600 2017-12-20
Nsx V Edge MEDIUM 5.9
CVE-2017-4920

The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the li…

Fix: 6.2.8 / 6.3.3+
Fix from $1,600 2017-12-05
Spring Security HIGH 8.1
CVE-2017-4995

An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. When configured to enable defau…

Mitigation only
Fix from $1,950 2017-11-27