Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fusion HIGH 7.8
CVE-2023-34045

VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation for the first time (the user n…

Fix: 13.5+
Fix from $1,950 2023-10-20
Fusion HIGH 7.0
CVE-2023-34046

VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (th…

Fix: 13.5+
Fix from $1,950 2023-10-20
Workstation MEDIUM 6.0
CVE-2023-34044

VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality …

Fix: 13.5 / 17.5+
Fix from $1,600 2023-10-20
Aria Operations For Logs HIGH 7.8
CVE-2023-34052

VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can tr…

Patch available
Fix from $1,950 2023-10-20
Aria Operations For Logs CRITICAL 9.8
CVE-2023-34051EPSS 45%

VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operat…

Patch available
Fix from $2,300 2023-10-20
Aria Operations MEDIUM 6.7
CVE-2023-34043

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can esca…

Fix: 4.4+
Fix from $1,600 2023-09-27
Tools HIGH 7.5
CVE-2023-20900

A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E…

Fix: 10.3.26 / 12.3.0+
Fix from $1,950 2023-08-31
Aria Operations For Networks CRITICAL 9.8
CVE-2023-34039EPSS 64%

Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor …

Fix: 6.11.0+
Fix from $2,300 2023-08-29
Aria Operations For Networks HIGH 7.2
CVE-2023-20890EPSS 22%

Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Ar…

Fix: 6.11.0+
Fix from $1,950 2023-08-29
Spring For Apache Kafka HIGH 7.8
CVE-2023-34040

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual c…

Fix: after 3.0.9
Fix from $1,950 2023-08-24
Horizon Client MEDIUM 5.3
CVE-2023-34038

VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relat…

Mitigation only
Fix from $1,600 2023-08-04
Horizon Client MEDIUM 5.3
CVE-2023-34037

VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requ…

Mitigation only
Fix from $1,600 2023-08-04
Isolation Segment MEDIUM 6.5
CVE-2023-20891

The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials …

Fix: 2.11.35 / 2.11.42+
Fix from $1,600 2023-07-26
Spring Security CRITICAL 9.8
CVE-2023-34034

Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebF…

Fix: 5.6.12 / 5.7.10+
Fix from $2,300 2023-07-19
Spring Security MEDIUM 5.3
CVE-2023-34035

Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration i…

Fix: 5.8.5 / 6.0.5+
Fix from $1,600 2023-07-18
Spring Hateoas MEDIUM 5.3
CVE-2023-34036

Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers if they are n…

Fix: 1.5.5 / 2.0.5+
Fix from $1,600 2023-07-17
Sd Wan Edge Firmware HIGH 7.5
CVE-2023-20899

VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the applicatio…

Fix: 4.5.2+
Fix from $1,950 2023-07-06
Vcenter Server HIGH 7.5
CVE-2023-20896

The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network a…

Fix: 7.0+
Fix from $1,950 2023-06-22
Vcenter Server CRITICAL 9.8
CVE-2023-20893

The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access…

Fix: 7.0+
Fix from $2,300 2023-06-22
Vcenter Server CRITICAL 9.8
CVE-2023-20894EPSS 34%

The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network …

Fix: 7.0+
Fix from $2,300 2023-06-22
Vcenter Server CRITICAL 9.8
CVE-2023-20895

The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network acc…

Fix: 7.0+
Fix from $2,300 2023-06-22
Vcenter Server CRITICAL 9.8
CVE-2023-20892

The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A ma…

Fix: 7.0+
Fix from $2,300 2023-06-22
Aria Operations For Networks CRITICAL 9.8
CVE-2023-20887 KEVEPSS 98%

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks…

Fix: after 6.10.0
Fix from $2,300 2023-06-07
Vrealize Network Insight HIGH 8.8
CVE-2023-20888EPSS 82%

Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations…

Fix: after 6.10.0
Fix from $1,950 2023-06-07
Vrealize Network Insight HIGH 7.5
CVE-2023-20889EPSS 79%

Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Ne…

Fix: after 6.10.0
Fix from $1,950 2023-06-07
Tools MEDIUM 5.5
CVE-2022-31693

VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious act…

Fix: 12.1.5+
Fix from $1,600 2023-06-07
Identity Manager MEDIUM 6.1
CVE-2023-20884

VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to…

Fix: after 22.09.1.0
Fix from $1,600 2023-05-30
Spring Boot HIGH 7.5
CVE-2023-20883

In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial…

Fix: 2.5.14+
Fix from $1,950 2023-05-26
Greenplum Database CRITICAL 9.1
CVE-2023-31131

Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods…

Fix: 6.22.3+
Fix from $2,300 2023-05-15
Cloud Foundation HIGH 8.8
CVE-2023-20877

VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execu…

Fix: after 4.5
Fix from $1,950 2023-05-12