Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Workstation MEDIUM 5.9
CVE-2022-22983

VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges …

Fix: 16.2.4+
Fix from $1,600 2022-08-10
Identity Manager CRITICAL 9.8
CVE-2022-31656EPSS 23%

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A …

Patch available
Fix from $2,300 2022-08-05
Identity Manager CRITICAL 9.8
CVE-2022-31657

VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect…

Patch available
Fix from $2,300 2022-08-05
Identity Manager HIGH 7.8
CVE-2022-31660

VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local acc…

Patch available
Fix from $1,950 2022-08-05
Identity Manager HIGH 7.8
CVE-2022-31661

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local …

Patch available
Fix from $1,950 2022-08-05
Identity Manager HIGH 7.8
CVE-2022-31664

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local acce…

Patch available
Fix from $1,950 2022-08-05
Identity Manager HIGH 7.5
CVE-2022-31662

VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with netw…

Patch available
Fix from $1,950 2022-08-05
Identity Manager HIGH 7.2
CVE-2022-31658

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administr…

Patch available
Fix from $1,950 2022-08-05
Identity Manager HIGH 7.2
CVE-2022-31659

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network acce…

Patch available
Fix from $1,950 2022-08-05
Identity Manager HIGH 7.2
CVE-2022-31665

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administr…

Patch available
Fix from $1,950 2022-08-05
Identity Manager MEDIUM 6.1
CVE-2022-31663

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper u…

Patch available
Fix from $1,600 2022-08-05
Cloud Foundation HIGH 7.5
CVE-2022-22982

The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server ma…

Fix: after 4.3.1
Fix from $1,950 2022-07-13
Vrealize Log Insight MEDIUM 5.4
CVE-2022-31654

VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in conf…

Fix: 8.8.2+
Fix from $1,600 2022-07-12
Vrealize Log Insight MEDIUM 5.4
CVE-2022-31655

VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in aler…

Fix: 8.8.2+
Fix from $1,600 2022-07-12
Spring Data Mongodb CRITICAL 9.8
CVE-2022-22980EPSS 18%

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions tha…

Fix: after 3.3.4
Fix from $2,300 2022-06-23
Spring Cloud Function HIGH 7.5
CVE-2022-22979

In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to ca…

Fix: 3.2.6+
Fix from $1,950 2022-06-21
Vmware Hcx MEDIUM 6.5
CVE-2022-22953

VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be ab…

Mitigation only
Fix from $1,600 2022-06-16
Tools HIGH 7.1
CVE-2022-22977

VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative lo…

Fix: 12.0.5+
Fix from $1,950 2022-05-24
Identity Manager CRITICAL 9.8
CVE-2022-22972EPSS 56%

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A …

Mitigation only
Fix from $2,300 2022-05-20
Identity Manager HIGH 7.8
CVE-2022-22973

VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privi…

Mitigation only
Fix from $1,950 2022-05-20
Spring Security CRITICAL 9.8
CVE-2022-22978EPSS 12%

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be b…

Fix: 5.5.7 / 5.6.4+
Fix from $2,300 2022-05-19
Spring Security MEDIUM 5.3
CVE-2022-22976

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When…

Fix: 5.5.7 / 5.6.4+
Fix from $1,600 2022-05-19
Spring Framework MEDIUM 6.5
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable …

Fix: after 5.3.19
Fix from $1,600 2022-05-12
Spring Framework MEDIUM 5.3
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS att…

Fix: after 5.3.19
Fix from $1,600 2022-05-12
Pinniped MEDIUM 6.6
CVE-2022-22975

An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would inv…

Fix: 0.17.0+
Fix from $1,600 2022-05-11
Vcloud Director HIGH 7.2
CVE-2022-22966EPSS 6%

An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider may be able to exploit a remote…

Fix: 10.1.4.1 / 10.2.2.3+
Fix from $1,950 2022-04-14
Spring Framework MEDIUM 5.3
CVE-2022-22968EPSS 6%

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are ca…

Fix: 5.2.0+
Fix from $1,600 2022-04-14
Cloud Foundation HIGH 7.8
CVE-2022-22960 KEVEPSS 36%

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in sup…

Fix: 5.0 / 9.0+
Fix from $1,950 2022-04-13
Cloud Foundation HIGH 7.2
CVE-2022-22957EPSS 23%

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22…

Fix: 5.0 / 9.0+
Fix from $1,950 2022-04-13
Cloud Foundation HIGH 7.2
CVE-2022-22958

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22…

Fix: 5.0 / 9.0+
Fix from $1,950 2022-04-13