Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2021-21992
The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user acce…
Cloud Foundation
3.10.2.2 / 4.3+
HIGH 8.4
CVE-2020-3960
VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) …
Fusion
11.5.5 / 15.5.5+
CRITICAL 9.8
CVE-2021-22002
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a …
Identity Manager
Patch available
HIGH 7.5
CVE-2021-22003
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to po…
Identity Manager
Patch available
HIGH 7.5
CVE-2021-22029
VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause…
Workspace One Uem Console
20.1.0.33 / 20.5.0.51+
MEDIUM 5.4
CVE-2021-22021
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker…
Cloud Foundation
4.3 / 8.4+
HIGH 7.5
CVE-2021-22024
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with net…
Cloud Foundation
8.5.0+
HIGH 7.5
CVE-2021-22025
The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unaut…
Cloud Foundation
8.5.0+
HIGH 7.5
CVE-2021-22026
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit…
Cloud Foundation
8.5.0+
HIGH 7.5
CVE-2021-22027
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit…
Cloud Foundation
8.5.0+
HIGH 7.2
CVE-2021-22023
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to v…
Cloud Foundation
8.5.0+
CRITICAL 9.8
CVE-2021-21994
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on E…
Cloud Foundation
3.10.2 / 4.3+
HIGH 7.8
CVE-2021-22000
VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administ…
Thinapp
5.2.10+
HIGH 7.5
CVE-2021-21995
OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 …
Cloud Foundation
3.10.2 / 4.3+
HIGH 7.5
CVE-2021-22119EPSS 6%
Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-S…
Spring Security
5.2.11 / 5.3.10+
MEDIUM 5.4
CVE-2021-32718
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the…
Rabbitmq
3.8.17+
CRITICAL 9.8
CVE-2021-21998EPSS 11%
VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network acc…
Carbon Black App Control
8.5.8 / 8.6.2+
HIGH 7.8
CVE-2021-21999
VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.1…
App Volumes
2.18.10 / 11.2.6+
MEDIUM 5.5
CVE-2021-21997
VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user …
Tools
11.3.0+
HIGH 7.5
CVE-2021-22116
RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection e…
Rabbitmq
3.8.16+
HIGH 7.8
CVE-2021-22118
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation:…
Spring Framework
5.2.15 / 5.3.7+
CRITICAL 9.8
CVE-2021-21985 KEVEPSS 100%
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whi…
Vcenter Server
3.10.2.1 / 4.2.1+
CRITICAL 9.8
CVE-2021-21986EPSS 13%
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Li…
Vcenter Server
3.10.2.1 / 4.2.1+
MEDIUM 6.5
CVE-2021-21987
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado…
Workstation
5.5.2 / 16.1.2+
MEDIUM 6.5
CVE-2021-21988
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado…
Workstation
5.5.2 / 16.1.2+
MEDIUM 6.5
CVE-2021-21989
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado…
Workstation
5.5.2 / 16.1.2+
MEDIUM 6.1
CVE-2021-21990
VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 2…
Workspace One Unified Endpoint Management
19.12.0.24 / 20.1.0.32+
CRITICAL 9.8
CVE-2021-21984
VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious ac…
Vrealize Business For Cloud
7.6.0+
CRITICAL 9.1
CVE-2021-21982
VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network …
Carbon Black Cloud Workload
after 1.0.1
HIGH 7.5
CVE-2021-21975 KEVEPSS 78%
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the v…
Cloud Foundation
Mitigation only