Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloud Foundation HIGH 7.2
CVE-2023-20878

VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and …

Fix: after 4.5
Fix from $1,950 2023-05-12
Cloud Foundation MEDIUM 6.7
CVE-2023-20879

VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations a…

Fix: after 4.5
Fix from $1,600 2023-05-12
Aria Operations MEDIUM 6.7
CVE-2023-20880

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate p…

Fix: 8.12.0+
Fix from $1,600 2023-05-12
Fusion HIGH 8.2
CVE-2023-20869

VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing h…

Fix: 13.0.2 / 17.0.2+
Fix from $1,950 2023-04-25
Fusion MEDIUM 6.0
CVE-2023-20870

VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with th…

Fix: 13.0.2 / 17.0.2+
Fix from $1,600 2023-04-25
Fusion HIGH 8.8
CVE-2023-20872

VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.

Mitigation only
Fix from $1,950 2023-04-25
Fusion HIGH 7.8
CVE-2023-20871

VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate …

Fix: 13.0.2+
Fix from $1,950 2023-04-25
Esxi HIGH 7.5
CVE-2023-29552 KEVEPSS 66%

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacke…

Fix: 7.0+
Fix from $1,950 2023-04-25
Aria Operations For Logs CRITICAL 9.8
CVE-2023-20864EPSS 70%

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Oper…

Fix: 8.12.0+
Fix from $2,300 2023-04-20
Spring Boot CRITICAL 9.8
CVE-2023-20873

In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susc…

Fix: 2.5.15 / 2.6.14+
Fix from $2,300 2023-04-20
Aria Operations For Logs HIGH 7.2
CVE-2023-20865

VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operation…

Fix: 8.12.0+
Fix from $1,950 2023-04-20
Spring Security MEDIUM 6.3
CVE-2023-20862

In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not prop…

Fix: 5.7.8 / 5.8.3+
Fix from $1,600 2023-04-19
Spring Session MEDIUM 6.5
CVE-2023-20866

In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to thos…

Mitigation only
Fix from $1,600 2023-04-13
Spring Framework MEDIUM 6.5
CVE-2023-20863

In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression …

Fix: 5.2.24 / 5.3.27+
Fix from $1,600 2023-04-13
Spring Framework HIGH 7.5
CVE-2023-20860

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher …

Fix: 5.3.26 / 6.0.7+
Fix from $1,950 2023-03-27
Spring Framework MEDIUM 6.5
CVE-2023-20861

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user…

Fix: after 6.0.6
Fix from $1,600 2023-03-23
Spring Cloud Config MEDIUM 5.5
CVE-2023-20859

In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sen…

Fix: 2.3.3 / 3.0.2+
Fix from $1,600 2023-03-23
Workspace One Content MEDIUM 6.8
CVE-2023-20857

VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass…

Fix: 23.02+
Fix from $1,600 2023-02-28
Vrealize Automation HIGH 8.8
CVE-2023-20855

VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orche…

Fix: 8.11.1+
Fix from $1,950 2023-02-22
Carbon Black App Control HIGH 7.2
CVE-2023-20858EPSS 17%

VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious …

Fix: 8.7.8 / 8.8.6+
Fix from $1,950 2023-02-22
Ixgben HIGH 7.8
CVE-2022-36416

Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.13 may allow an authenticated us…

Fix: 1.10.0.13+
Fix from $1,950 2023-02-16
Ixgben MEDIUM 5.5
CVE-2022-36797

Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.1 may allow an authenticated use…

Fix: 1.10.0.1+
Fix from $1,600 2023-02-16
Workstation HIGH 8.4
CVE-2023-20854

VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploi…

Patch available
Fix from $1,950 2023-02-03
Vrealize Operations HIGH 8.8
CVE-2023-20856

VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of th…

Fix: after 8.6.4
Fix from $1,950 2023-02-01
Vrealize Log Insight HIGH 7.5
CVE-2022-31710

vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrust…

Fix: 8.10.2+
Fix from $1,950 2023-01-26
Vrealize Log Insight MEDIUM 5.3
CVE-2022-31711EPSS 22%

VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and applicatio…

Fix: 8.10.2+
Fix from $1,600 2023-01-26
Vrealize Log Insight CRITICAL 9.8
CVE-2022-31704EPSS 81%

The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive f…

Fix: 8.10.2+
Fix from $2,300 2023-01-26
Vrealize Log Insight CRITICAL 9.8
CVE-2022-31706EPSS 87%

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system…

Fix: 8.10.2+
Fix from $2,300 2023-01-26
Vrealize Operations HIGH 7.2
CVE-2022-31707

vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important sev…

Fix: 8.6.4.20823815+
Fix from $1,950 2022-12-16
Vrealize Network Insight CRITICAL 9.8
CVE-2022-31702

vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the…

Patch available
Fix from $2,300 2022-12-14