Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Workstation HIGH 8.2
CVE-2022-31705

VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local …

Fix: 12.2.5 / 16.2.5+
Fix from $1,950 2022-12-14
Vrealize Log Insight HIGH 7.5
CVE-2022-31703

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system…

Fix: after 8.10.1
Fix from $1,950 2022-12-14
Access HIGH 7.2
CVE-2022-31700

VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of t…

Mitigation only
Fix from $1,950 2022-12-14
Access MEDIUM 5.3
CVE-2022-31701

VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be…

Mitigation only
Fix from $1,600 2022-12-14
Cloud Foundation HIGH 8.8
CVE-2022-31696

VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESX…

Fix: 3.10 / 4.3.11+
Fix from $1,950 2022-12-13
Vcenter Server MEDIUM 5.5
CVE-2022-31697

The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to …

Mitigation only
Fix from $1,600 2022-12-13
Cloud Foundation MEDIUM 5.3
CVE-2022-31698EPSS 48%

The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vC…

Mitigation only
Fix from $1,600 2022-12-13
Open Vm Tools HIGH 7.0
CVE-2009-1143

An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink atta…

Patch available
Fix from $1,950 2022-11-23
Open Vm Tools MEDIUM 6.7
CVE-2009-1142

An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wr…

Mitigation only
Fix from $1,600 2022-11-23
Hyperic Agent CRITICAL 9.9
CVE-2022-38652

A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authent…

Mitigation only
Fix from $2,300 2022-11-12
Hyperic Server CRITICAL 9.8
CVE-2022-38651

A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some…

Mitigation only
Fix from $2,300 2022-11-12
Hyperic Server CRITICAL 10.0
CVE-2022-38650

A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a m…

Mitigation only
Fix from $2,300 2022-11-12
Workspace One Assist CRITICAL 9.8
CVE-2022-31685

VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE As…

Fix: 22.10+
Fix from $2,300 2022-11-09
Workspace One Assist CRITICAL 9.8
CVE-2022-31686

VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace …

Fix: 22.10+
Fix from $2,300 2022-11-09
Workspace One Assist CRITICAL 9.8
CVE-2022-31687

VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Ass…

Fix: 22.10+
Fix from $2,300 2022-11-09
Workspace One Assist CRITICAL 9.8
CVE-2022-31689

VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able…

Fix: 22.10+
Fix from $2,300 2022-11-09
Workspace One Assist MEDIUM 6.1
CVE-2022-31688

VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a …

Fix: 22.10+
Fix from $1,600 2022-11-09
Bosh Editor CRITICAL 9.8
CVE-2022-31691

Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor…

Fix: 1.40.0 / 4.16.1+
Fix from $2,300 2022-11-04
Spring Security CRITICAL 9.8
CVE-2022-31692

Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatc…

Fix: 5.6.9 / 5.7.5+
Fix from $2,300 2022-10-31
Spring Security HIGH 8.1
CVE-2022-31690

Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation u…

Fix: 5.6.9 / 5.7.5+
Fix from $1,950 2022-10-31
Cloud Foundation CRITICAL 9.1
CVE-2022-31678EPSS 8%

VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user …

Fix: 3.11 / 6.4.14+
Fix from $2,300 2022-10-28
Vcenter Server CRITICAL 9.1
CVE-2022-31680EPSS 33%

The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on…

Fix: 6.5+
Fix from $2,300 2022-10-07
Cloud Foundation MEDIUM 6.5
CVE-2022-31681

VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of se…

Fix: 4.3.1.1 / 7.0+
Fix from $1,600 2022-10-07
Rabbitmq HIGH 7.5
CVE-2022-31008

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their …

Fix: 3.8.32 / 3.9.18+
Fix from $1,950 2022-10-06
Pinniped MEDIUM 5.4
CVE-2022-31677

An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via…

Fix: 0.19.0+
Fix from $1,600 2022-08-29
Tools HIGH 7.8
CVE-2022-31676

VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access …

Fix: 10.3.25 / 12.1.0+
Fix from $1,950 2022-08-23
Ixgben MEDIUM 5.5
CVE-2022-21793

Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Et…

Fix: 1.11.4.0 / 2.1.5.0+
Fix from $1,600 2022-08-18
Vrealize Operations HIGH 7.5
CVE-2022-31675

VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to cre…

Fix: 8.6.4+
Fix from $1,950 2022-08-10
Vrealize Operations HIGH 8.8
CVE-2022-31673

VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak…

Fix: 8.6.4+
Fix from $1,950 2022-08-10
Vrealize Operations HIGH 7.2
CVE-2022-31672

VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privilege…

Fix: 8.6.4+
Fix from $1,950 2022-08-10