Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-22049 The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A maliciou… Vcenter Server Patch available Fix from $2,3002021-11-24 HIGH 7.5 CVE-2021-21980 The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on … Cloud Foundation Patch available Fix from $1,9502021-11-24 HIGH 8.8 CVE-2021-22053EPSS 13% Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within th… Spring Cloud Netflix 2.2.10+ Fix from $1,9502021-11-19 HIGH 8.8 CVE-2021-22048EPSS 10% The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious… Cloud Foundation after 4.1.0.1 Fix from $1,9502021-11-10 MEDIUM 6.5 CVE-2021-22051 Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. User… Spring Cloud Gateway 2.2.10 / 3.0.5+ Fix from $1,6002021-11-08 HIGH 8.8 CVE-2021-22038 On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so i… Installbuilder 21.6.0+ Fix from $1,9502021-10-29 HIGH 7.8 CVE-2021-22037 Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is … Installbuilder 21.6.0+ Fix from $1,9502021-10-29 MEDIUM 6.5 CVE-2021-22097 In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a me… Spring Advanced Message Queuing Protocol after 2.3.10 Fix from $1,6002021-10-28 HIGH 7.5 CVE-2021-22044 In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapp… Spring Cloud Openfeign after 3.0.4 Fix from $1,9502021-10-28 MEDIUM 5.3 CVE-2021-22047 In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a … Spring Data Rest after 3.5.5 Fix from $1,6002021-10-28 HIGH 7.5 CVE-2021-22034 Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability. Vrealize Operations Tenant 8.6+ Fix from $1,9502021-10-21 MEDIUM 6.5 CVE-2021-22036 VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able… Vrealize Automation 8.6+ Fix from $1,6002021-10-13 HIGH 7.5 CVE-2021-22019 The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vC… Cloud Foundation 3.10.2.2 / 4.3+ Fix from $1,9502021-09-23 MEDIUM 6.5 CVE-2021-22018 The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network a… Cloud Foundation 4.3.1+ Fix from $1,6002021-09-23 MEDIUM 6.1 CVE-2021-22016 The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to… Cloud Foundation 5.0+ Fix from $1,6002021-09-23 MEDIUM 5.5 CVE-2021-22020 The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker t… Cloud Foundation 3.10.2.2 / 4.3+ Fix from $1,6002021-09-23 MEDIUM 5.3 CVE-2021-22017 KEVEPSS 49% Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acce… Vcenter Server Patch available Fix from $1,6002021-09-23 HIGH 7.8 CVE-2021-22015 The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticate… Cloud Foundation 5.0+ Fix from $1,9502021-09-23 HIGH 7.5 CVE-2021-22012 The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with networ… Cloud Foundation 5.0+ Fix from $1,9502021-09-23 HIGH 7.5 CVE-2021-22013 The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor … Cloud Foundation 5.0+ Fix from $1,9502021-09-23 HIGH 7.2 CVE-2021-22014 The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAM… Cloud Foundation 5.0+ Fix from $1,9502021-09-23 CRITICAL 9.8 CVE-2021-22005 KEVEPSS 100% The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCe… Cloud Foundation 5.0+ Fix from $2,3002021-09-23 HIGH 7.5 CVE-2021-22006EPSS 6% The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access t… Cloud Foundation 5.0+ Fix from $1,9502021-09-23 HIGH 7.5 CVE-2021-22008 The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 … Cloud Foundation 5.0+ Fix from $1,9502021-09-23 HIGH 7.5 CVE-2021-22009 The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 4… Cloud Foundation 5.0+ Fix from $1,9502021-09-23 HIGH 7.5 CVE-2021-22010 The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server ma… Cloud Foundation 5.0+ Fix from $1,9502021-09-23 MEDIUM 6.5 CVE-2021-21993 The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library.… Cloud Foundation 5.0+ Fix from $1,6002021-09-23 MEDIUM 5.5 CVE-2021-22007 The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative priv… Cloud Foundation 5.0+ Fix from $1,6002021-09-23 MEDIUM 5.3 CVE-2021-22011 vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to por… Cloud Foundation 5.0+ Fix from $1,6002021-09-23 HIGH 7.8 CVE-2021-21991 The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administr… Cloud Foundation 3.10.2.2 / 4.3+ Fix from $1,9502021-09-22