Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2021-21983EPSS 69% Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with n… Cloud Foundation No fix yet Fix from $1,6002021-03-31 CRITICAL 9.8 CVE-2021-26987 Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability… Spring Boot 1.3.2 / 2.17.56+ Fix from $2,3002021-03-15 CRITICAL 9.8 CVE-2021-21978EPSS 99% VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authoriza… View Planner 4.6+ Fix from $2,3002021-03-03 MEDIUM 5.3 CVE-2021-22114 Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write vulnerability, that can be a… Spring Integration Zip 1.0.4+ Fix from $1,6002021-03-01 HIGH 8.8 CVE-2021-21974EPSS 45% OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnera… Cloud Foundation 3.10.1.2 / 4.2+ Fix from $1,9502021-02-24 CRITICAL 9.8 CVE-2021-21972 KEVEPSS 100% The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 4… Cloud Foundation 3.10.1.2 / 4.2+ Fix from $2,3002021-02-24 MEDIUM 5.3 CVE-2021-21973 KEVEPSS 88% The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin… Cloud Foundation 3.10.1.2 / 4.2+ Fix from $1,6002021-02-24 HIGH 8.8 CVE-2021-22112 Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the… Spring Security 5.2.9 / 5.3.8+ Fix from $1,9502021-02-23 MEDIUM 5.3 CVE-2021-22113 Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sen… Spring Cloud Netflix Zuul after 2.2.6 Fix from $1,6002021-02-23 HIGH 7.2 CVE-2021-21976 vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication c… Vsphere Replication 6.5.1.5 / 8.1.2.3+ Fix from $1,9502021-02-11 HIGH 7.2 CVE-2020-5427 In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting t… Spring Cloud Data Flow 2.5.4 / 2.6.5+ Fix from $1,9502021-01-27 MEDIUM 6.0 CVE-2020-5428 In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising certain lookup queries in the Tas… Spring Cloud Task after 2.2.4 Fix from $1,6002021-01-27 MEDIUM 6.5 CVE-2020-3999 VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 an… Workstation 11.5.7 / 15.5.7+ Fix from $1,6002020-12-21 CRITICAL 9.8 CVE-2020-4001 The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default pas… Sd Wan Orchestrator after 4.0.1 Fix from $2,3002020-11-24 HIGH 8.8 CVE-2020-3985 The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization levels leading to a privileg… Sd Wan Orchestrator 3.4.4+ Fix from $1,9502020-11-24 HIGH 8.8 CVE-2020-4000EPSS 43% The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversa… Sd Wan Orchestrator 3.4.4 / 4.0.1+ Fix from $1,9502020-11-24 HIGH 7.2 CVE-2020-4002 The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An auth… Sd Wan Orchestrator 3.4.4 / 4.0.1+ Fix from $1,9502020-11-24 MEDIUM 6.5 CVE-2020-3984EPSS 22% The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An a… Sd Wan Orchestrator 3.4.4+ Fix from $1,6002020-11-24 MEDIUM 6.5 CVE-2020-4003 VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attack… Sd Wan Orchestrator 3.4.4 / 4.0.1+ Fix from $1,6002020-11-24 CRITICAL 9.1 CVE-2020-4006 KEVEPSS 17% VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. Identity Manager after 8.2 Fix from $2,3002020-11-23 HIGH 8.2 CVE-2020-4004 VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusi… Fusion 3.10.1.2 / 4.1.0.1+ Fix from $1,9502020-11-20 HIGH 7.8 CVE-2020-4005 VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege-escalation vulnera… Cloud Foundation 3.10.1.2 / 4.1.0.1+ Fix from $1,9502020-11-20 CRITICAL 9.8 CVE-2020-5426 Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also… Pivotal Scheduler 1.4.0+ Fix from $2,3002020-11-11 HIGH 7.9 CVE-2020-5425 Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user imper… Single Sign On For Tanzu 1.11.3 / 1.12.4+ Fix from $1,9502020-10-31 MEDIUM 6.5 CVE-2020-3998 VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges o… Horizon Client 5.5.0+ Fix from $1,6002020-10-23 MEDIUM 5.4 CVE-2020-3997 VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may … Horizon 7.10.3 / 7.13.0+ Fix from $1,6002020-10-23 MEDIUM 5.5 CVE-2020-3996 Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in information leakage to unauthorize… Velero 1.4.3 / 1.5.2+ Fix from $1,6002020-10-22 MEDIUM 5.3 CVE-2020-3995 In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the… Esxi 3.9 / 11.1.0+ Fix from $1,6002020-10-20 CRITICAL 9.8 CVE-2020-3992 KEVEPSS 83% OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after… Cloud Foundation 3.10.1.2 / 4.1.0.1+ Fix from $2,3002020-10-20 HIGH 7.7 CVE-2020-3982 VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x … Esxi 3.10.1 / 4.1+ Fix from $1,9502020-10-20