Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2022-22961
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess informa…
Cloud Foundation
5.0 / 9.0+
CRITICAL 9.8
CVE-2022-22955EPSS 8%
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious …
Identity Manager
9.0+
CRITICAL 9.8
CVE-2022-22956EPSS 51%
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious …
Identity Manager
9.0+
CRITICAL 9.8
CVE-2022-22954 KEVEPSS 100%
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious act…
Identity Manager
after 8.2
HIGH 7.8
CVE-2022-22962
VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location d…
Horizon
2203+
HIGH 7.8
CVE-2022-22964
VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable confi…
Horizon
2203+
MEDIUM 5.3
CVE-2021-22055
The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious …
Photon Os
2022-02-16+
CRITICAL 9.8
CVE-2022-22963 KEVEPSS 100%
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide …
Spring Cloud Function
after 3.2.2
CRITICAL 9.8
CVE-2022-22965 KEVEPSS 100%
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit …
Spring Framework
2.1.0 / 5.2.20+
MEDIUM 6.5
CVE-2022-22950EPSS 36%
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression t…
Spring Framework
5.2.20 / 5.3.17+
HIGH 7.8
CVE-2022-27772
spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springfram…
Spring Boot
2.2.11+
MEDIUM 6.5
CVE-2022-22948 KEVEPSS 13%
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative ac…
Cloud Foundation
3.11 / 4.4.1+
CRITICAL 9.1
CVE-2022-22951EPSS 20%
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command i…
Carbon Black App Control
8.5.14 / 8.6.6+
CRITICAL 9.1
CVE-2022-22952
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload v…
Carbon Black App Control
8.5.14 / 8.6.6+
MEDIUM 5.5
CVE-2022-22946
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set …
Spring Cloud Gateway
Patch available
CRITICAL 10.0
CVE-2022-22947 KEVEPSS 98%
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoi…
Spring Cloud Gateway
3.0.7+
MEDIUM 6.7
CVE-2022-22943
VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local adminis…
Tools
12.0.0+
MEDIUM 5.4
CVE-2022-22944
VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Wor…
Workspace One Boxer
22.02+
HIGH 7.8
CVE-2022-22945
VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary comman…
Cloud Foundation
6.4.13+
HIGH 7.8
CVE-2021-22042
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privile…
Cloud Foundation
4.4+
HIGH 7.5
CVE-2021-22043
VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with ac…
Fusion
4.4+
HIGH 7.5
CVE-2021-22050
ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to…
Cloud Foundation
3.11 / 4.4+
MEDIUM 6.7
CVE-2021-22040
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative p…
Cloud Foundation
3.11 / 4.4+
MEDIUM 6.7
CVE-2021-22041
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative pri…
Cloud Foundation
3.11 / 4.4+
MEDIUM 6.5
CVE-2022-22938
VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Corta…
Workstation
5.5.3 / 16.2.2+
HIGH 7.8
CVE-2021-22045
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contai…
Cloud Foundation
12.2.0 / 16.2.0+
HIGH 8.8
CVE-2021-22057
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provi…
Workspace One Access
Patch available
HIGH 7.5
CVE-2021-22056
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor…
Identity Manager
after 8.6
HIGH 7.5
CVE-2021-22054 KEVEPSS 97%
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 con…
Workspace One Uem Console
20.0.8.36 / 20.11.0.40+
MEDIUM 6.5
CVE-2021-22095
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object …
Spring Advanced Message Queuing Protocol
2.2.19 / 2.3.11+