Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2021-21992 The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user acce… Cloud Foundation 3.10.2.2 / 4.3+ Fix from $1,6002021-09-22 HIGH 8.4 CVE-2020-3960 VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) … Fusion 11.5.5 / 15.5.5+ Fix from $1,9502021-09-15 CRITICAL 9.8 CVE-2021-22002 VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a … Identity Manager Patch available Fix from $2,3002021-08-31 HIGH 7.5 CVE-2021-22003 VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to po… Identity Manager Patch available Fix from $1,9502021-08-31 HIGH 7.5 CVE-2021-22029 VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause… Workspace One Uem Console 20.1.0.33 / 20.5.0.51+ Fix from $1,9502021-08-31 MEDIUM 5.4 CVE-2021-22021 VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker… Cloud Foundation 4.3 / 8.4+ Fix from $1,6002021-08-30 HIGH 7.5 CVE-2021-22024 The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with net… Cloud Foundation 8.5.0+ Fix from $1,9502021-08-30 HIGH 7.5 CVE-2021-22025 The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unaut… Cloud Foundation 8.5.0+ Fix from $1,9502021-08-30 HIGH 7.5 CVE-2021-22026 The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit… Cloud Foundation 8.5.0+ Fix from $1,9502021-08-30 HIGH 7.5 CVE-2021-22027 The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor wit… Cloud Foundation 8.5.0+ Fix from $1,9502021-08-30 HIGH 7.2 CVE-2021-22023 The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to v… Cloud Foundation 8.5.0+ Fix from $1,9502021-08-30 CRITICAL 9.8 CVE-2021-21994 SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on E… Cloud Foundation 3.10.2 / 4.3+ Fix from $2,3002021-07-13 HIGH 7.8 CVE-2021-22000 VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administ… Thinapp 5.2.10+ Fix from $1,9502021-07-13 HIGH 7.5 CVE-2021-21995 OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 … Cloud Foundation 3.10.2 / 4.3+ Fix from $1,9502021-07-13 HIGH 7.5 CVE-2021-22119EPSS 6% Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-S… Spring Security 5.2.11 / 5.3.10+ Fix from $1,9502021-06-29 MEDIUM 5.4 CVE-2021-32718 RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the… Rabbitmq 3.8.17+ Fix from $1,6002021-06-28 CRITICAL 9.8 CVE-2021-21998EPSS 11% VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network acc… Carbon Black App Control 8.5.8 / 8.6.2+ Fix from $2,3002021-06-23 HIGH 7.8 CVE-2021-21999 VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.1… App Volumes 2.18.10 / 11.2.6+ Fix from $1,9502021-06-23 MEDIUM 5.5 CVE-2021-21997 VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user … Tools 11.3.0+ Fix from $1,6002021-06-18 HIGH 7.5 CVE-2021-22116 RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection e… Rabbitmq 3.8.16+ Fix from $1,9502021-06-08 HIGH 7.8 CVE-2021-22118 In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation:… Spring Framework 5.2.15 / 5.3.7+ Fix from $1,9502021-05-27 CRITICAL 9.8 CVE-2021-21985 KEVEPSS 100% The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whi… Vcenter Server 3.10.2.1 / 4.2.1+ Fix from $2,3002021-05-26 CRITICAL 9.8 CVE-2021-21986EPSS 13% The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Li… Vcenter Server 3.10.2.1 / 4.2.1+ Fix from $2,3002021-05-26 MEDIUM 6.5 CVE-2021-21987 VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado… Workstation 5.5.2 / 16.1.2+ Fix from $1,6002021-05-24 MEDIUM 6.5 CVE-2021-21988 VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado… Workstation 5.5.2 / 16.1.2+ Fix from $1,6002021-05-24 MEDIUM 6.5 CVE-2021-21989 VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado… Workstation 5.5.2 / 16.1.2+ Fix from $1,6002021-05-24 MEDIUM 6.1 CVE-2021-21990 VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 2… Workspace One Unified Endpoint Management 19.12.0.24 / 20.1.0.32+ Fix from $1,6002021-05-11 CRITICAL 9.8 CVE-2021-21984 VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious ac… Vrealize Business For Cloud 7.6.0+ Fix from $2,3002021-05-07 CRITICAL 9.1 CVE-2021-21982 VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network … Carbon Black Cloud Workload after 1.0.1 Fix from $2,3002021-04-01 HIGH 7.5 CVE-2021-21975 KEVEPSS 78% Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the v… Cloud Foundation Mitigation only Fix from $1,9502021-03-31