Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloud Foundation HIGH 7.5
CVE-2025-22243

VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.

Fix: 4.1.2.6 / 4.2.1.4+
Fix from $1,950 2025-06-04
Cloud Foundation MEDIUM 6.9
CVE-2025-22244

VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.

Fix: 4.1.2.6 / 4.2.1.4+
Fix from $1,600 2025-06-04
Cloud Foundation MEDIUM 5.9
CVE-2025-22245

VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.

Fix: 4.1.2.6 / 4.2.1.4+
Fix from $1,600 2025-06-04
Cloud Foundation HIGH 7.3
CVE-2025-41231

VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be abl…

Fix: 4.5.2 / 5.2.1.2+
Fix from $1,950 2025-05-20
Aria Automation HIGH 8.2
CVE-2025-22249

VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access to…

Fix: after 5.2.1
Fix from $1,950 2025-05-13
Esxi HIGH 8.2
CVE-2025-22224 KEV

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with …

Fix: 17.6.3+
Fix from $1,950 2025-03-04
Esxi HIGH 8.2
CVE-2025-22225 KEV

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write…

Mitigation only
Fix from $1,950 2025-03-04
Esxi MEDIUM 6.0
CVE-2025-22226 KEV

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with adm…

Fix: 13.6.3 / 17.6.3+
Fix from $1,600 2025-03-04
Aria Operations For Logs CRITICAL 9.0
CVE-2025-22219

VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be abl…

Fix: 8.18.3+
Fix from $2,300 2025-01-30
Aria Operations MEDIUM 6.5
CVE-2025-22222

VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnera…

Fix: 8.18.3+
Fix from $1,600 2025-01-30
Aria Operations For Logs MEDIUM 5.4
CVE-2025-22220

VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network acces…

Fix: 8.18.3+
Fix from $1,600 2025-01-30
Aria Operations For Logs HIGH 7.7
CVE-2025-22218

VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to r…

Fix: 8.18.3+
Fix from $1,950 2025-01-30
Aria Operations HIGH 7.8
CVE-2024-38830

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this v…

Fix: 8.18.2+
Fix from $1,950 2024-11-26
Aria Operations HIGH 7.8
CVE-2024-38831

VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malici…

Fix: 8.18.2+
Fix from $1,950 2024-11-26
Aria Operations MEDIUM 6.4
CVE-2024-38832

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject mal…

Fix: 8.18.2+
Fix from $1,600 2024-11-26
Aria Operations MEDIUM 5.4
CVE-2024-38833

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject ma…

Fix: 8.18.2+
Fix from $1,600 2024-11-26
Spring Framework MEDIUM 5.3
CVE-2024-38820

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exc…

Fix: 5.3.41 / 6.0.25+
Fix from $1,600 2024-10-18
Vmware Hcx HIGH 8.8
CVE-2024-38814EPSS 15%

An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator p…

Fix: after 4.9.1
Fix from $1,950 2024-10-16
Cloud Foundation CRITICAL 9.8
CVE-2024-38813 KEVEPSS 17%

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerabil…

Fix: 5.2+
Fix from $2,300 2024-09-17
Cloud Foundation CRITICAL 9.8
CVE-2024-38812 KEVEPSS 55%

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCen…

Fix: 5.2+
Fix from $2,300 2024-09-17
Fusion HIGH 7.8
CVE-2024-38811

VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with…

Fix: 13.6+
Fix from $1,950 2024-09-03
Spring Security HIGH 7.5
CVE-2024-38810

Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.

Fix: 6.3.2+
Fix from $1,950 2024-08-20
Spring Cloud Data Flow HIGH 8.8
CVE-2024-37084EPSS 35%

In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to wr…

Fix: 2.11.4+
Fix from $1,950 2024-07-25
Aria Automation HIGH 8.1
CVE-2024-22280

VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could e…

Fix: 8.17.0+
Fix from $1,950 2024-07-11
Cloud Director MEDIUM 5.4
CVE-2024-22277

VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availa…

Fix: 4.7.2+
Fix from $1,600 2024-07-04
Cloud Foundation HIGH 7.2
CVE-2024-37085 KEVEPSS 26%

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access…

Fix: 5.2+
Fix from $1,950 2024-06-25
Cloud Foundation MEDIUM 6.8
CVE-2024-37086

VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an exist…

Fix: 5.2+
Fix from $1,600 2024-06-25
Cloud Foundation MEDIUM 5.3
CVE-2024-37087

The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service…

Fix: 5.2+
Fix from $1,600 2024-06-25
Cloud Foundation CRITICAL 9.8
CVE-2024-37079 KEVEPSS 22%

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter …

Fix: 5.2+
Fix from $2,300 2024-06-18
Vcenter Server CRITICAL 9.8
CVE-2024-37080EPSS 12%

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter …

Patch available
Fix from $2,300 2024-06-18