Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vcenter Server HIGH 7.8
CVE-2024-37081

The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non…

Fix: 5.2+
Fix from $1,950 2024-06-18
Cloud Foundation HIGH 7.2
CVE-2024-22274

The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter app…

Fix: 5.1.1+
Fix from $1,950 2024-05-21
Cloud Foundation HIGH 7.8
CVE-2024-22273

The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtu…

Fix: 5.1.1 / 13.5.1+
Fix from $1,950 2024-05-21
Workstation MEDIUM 6.0
CVE-2024-22270

VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor …

Fix: 13.5.2 / 17.5.2+
Fix from $1,600 2024-05-14
Workstation MEDIUM 6.0
CVE-2024-22269

VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative p…

Fix: 13.5.2 / 17.5.2+
Fix from $1,600 2024-05-14
Workstation MEDIUM 6.5
CVE-2024-22268

VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative acc…

Fix: 13.5.2 / 17.5.2+
Fix from $1,600 2024-05-14
Fusion HIGH 8.2
CVE-2024-22267

VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges…

Fix: 13.5.2 / 17.5.2+
Fix from $1,950 2024-05-14
Spring Framework HIGH 8.1
CVE-2024-22259

Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform valid…

Fix: 5.3.33 / 6.0.18+
Fix from $1,950 2024-03-16
Cloud Foundation HIGH 8.2
CVE-2024-22254

VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds writ…

Fix: after 5.0
Fix from $1,950 2024-03-05
Cloud Foundation HIGH 7.1
CVE-2024-22255

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrativ…

Fix: 13.5.1 / 17.5.1+
Fix from $1,950 2024-03-05
Workstation MEDIUM 6.7
CVE-2024-22252

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative p…

Fix: 13.5.1 / 17.5.1+
Fix from $1,600 2024-03-05
Cloud Foundation MEDIUM 6.7
CVE-2024-22253

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative p…

Fix: 13.5.1 / 17.5.1+
Fix from $1,600 2024-03-05
Aria Operations MEDIUM 6.7
CVE-2024-22235

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can esca…

Fix: 8.16.0+
Fix from $1,600 2024-02-21
Spring Security HIGH 7.4
CVE-2024-22234

In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it di…

Fix: 6.1.7 / 6.2.2+
Fix from $1,950 2024-02-20
Aria Operations For Networks HIGH 7.8
CVE-2024-22237

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl…

Fix: after 6.12.0
Fix from $1,950 2024-02-06
Aria Operations For Networks HIGH 7.8
CVE-2024-22239

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl…

Fix: after 6.12.0
Fix from $1,950 2024-02-06
Spring Security MEDIUM 5.5
CVE-2023-34042

The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by a…

Fix: 5.8.7 / 6.0.7+
Fix from $1,600 2024-02-05
Spring Cloud Contract MEDIUM 5.5
CVE-2024-22236

In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnera…

Fix: 3.1.10 / 4.0.5+
Fix from $1,600 2024-01-31
Spring Framework HIGH 7.5
CVE-2024-22233

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-servic…

Mitigation only
Fix from $1,950 2024-01-22
Aria Automation HIGH 8.3
CVE-2023-34063

Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauth…

Patch available
Fix from $1,950 2024-01-16
Photon Os HIGH 7.8
CVE-2022-22942

The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processe…

Mitigation only
Fix from $1,950 2023-12-13
Spring Boot MEDIUM 6.5
CVE-2023-34055

In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may c…

Fix: after 3.1.5
Fix from $1,600 2023-11-28
Spring Framework HIGH 7.5
CVE-2023-34053

In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service …

Fix: 6.0.14+
Fix from $1,950 2023-11-28
Cloud Director CRITICAL 9.8
CVE-2023-34060

VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an …

Fix: 10.5+
Fix from $2,300 2023-11-14
Workspace One Uem MEDIUM 6.1
CVE-2023-20886

VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and ret…

Fix: 22.3.0.48 / 22.6.0.36+
Fix from $1,600 2023-10-31
Open Vm Tools HIGH 7.0
CVE-2023-34059

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able…

Fix: after 12.3.0
Fix from $1,950 2023-10-27
Tools HIGH 7.8
CVE-2023-34057

VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate pri…

Fix: 12.1.1+
Fix from $1,950 2023-10-27
Open Vm Tools HIGH 7.5
CVE-2023-34058

VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.v…

Fix: 12.3.5+
Fix from $1,950 2023-10-27
Rabbitmq Java Client HIGH 7.5
CVE-2023-46120

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used …

Fix: 5.18.0+
Fix from $1,950 2023-10-25
Vcenter Server CRITICAL 9.8
CVE-2023-34048 KEVEPSS 99%

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to v…

Fix: after 5.5
Fix from $2,300 2023-10-25