Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2021-22049
The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A maliciou…
Vcenter Server
Patch available
HIGH 7.5
CVE-2021-21980
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on …
Cloud Foundation
Patch available
HIGH 8.8
CVE-2021-22053EPSS 13%
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within th…
Spring Cloud Netflix
2.2.10+
HIGH 8.8
CVE-2021-22048EPSS 10%
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious…
Cloud Foundation
after 4.1.0.1
MEDIUM 6.5
CVE-2021-22051
Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. User…
Spring Cloud Gateway
2.2.10 / 3.0.5+
HIGH 8.8
CVE-2021-22038
On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so i…
Installbuilder
21.6.0+
HIGH 7.8
CVE-2021-22037
Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is …
Installbuilder
21.6.0+
MEDIUM 6.5
CVE-2021-22097
In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a me…
Spring Advanced Message Queuing Protocol
after 2.3.10
HIGH 7.5
CVE-2021-22044
In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapp…
Spring Cloud Openfeign
after 3.0.4
MEDIUM 5.3
CVE-2021-22047
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a …
Spring Data Rest
after 3.5.5
HIGH 7.5
CVE-2021-22034
Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability.
Vrealize Operations Tenant
8.6+
MEDIUM 6.5
CVE-2021-22036
VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able…
Vrealize Automation
8.6+
HIGH 7.5
CVE-2021-22019
The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vC…
Cloud Foundation
3.10.2.2 / 4.3+
MEDIUM 6.5
CVE-2021-22018
The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network a…
Cloud Foundation
4.3.1+
MEDIUM 6.1
CVE-2021-22016
The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to…
Cloud Foundation
5.0+
MEDIUM 5.5
CVE-2021-22020
The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker t…
Cloud Foundation
3.10.2.2 / 4.3+
MEDIUM 5.3
CVE-2021-22017 KEVEPSS 49%
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acce…
Vcenter Server
Patch available
HIGH 7.8
CVE-2021-22015
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticate…
Cloud Foundation
5.0+
HIGH 7.5
CVE-2021-22012
The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with networ…
Cloud Foundation
5.0+
HIGH 7.5
CVE-2021-22013
The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor …
Cloud Foundation
5.0+
HIGH 7.2
CVE-2021-22014
The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAM…
Cloud Foundation
5.0+
CRITICAL 9.8
CVE-2021-22005 KEVEPSS 100%
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCe…
Cloud Foundation
5.0+
HIGH 7.5
CVE-2021-22006EPSS 6%
The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access t…
Cloud Foundation
5.0+
HIGH 7.5
CVE-2021-22008
The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 …
Cloud Foundation
5.0+
HIGH 7.5
CVE-2021-22009
The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 4…
Cloud Foundation
5.0+
HIGH 7.5
CVE-2021-22010
The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server ma…
Cloud Foundation
5.0+
MEDIUM 6.5
CVE-2021-21993
The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library.…
Cloud Foundation
5.0+
MEDIUM 5.5
CVE-2021-22007
The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative priv…
Cloud Foundation
5.0+
MEDIUM 5.3
CVE-2021-22011
vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to por…
Cloud Foundation
5.0+
HIGH 7.8
CVE-2021-21991
The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administr…
Cloud Foundation
3.10.2.2 / 4.3+