Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2020-3958
VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x be…
Fusion
11.5.2 / 15.5.2+
HIGH 8.8
CVE-2020-3956EPSS 21%
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input…
Vcloud Director
9.1.0.4 / 9.5.0.6+
MEDIUM 6.5
CVE-2020-5408
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fix…
Spring Security
4.2.16 / 5.0.16+
CRITICAL 9.3
CVE-2020-3955
ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-202004103-SG do not properly neutralize script-related HTML when viewi…
Esxi
Patch available
HIGH 7.5
CVE-2020-3946
InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to Billion lau…
Installbuilder
19.11.0+
MEDIUM 6.1
CVE-2020-3954
Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
Vrealize Log Insight
8.1.0+
MEDIUM 6.5
CVE-2020-5406
VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes…
Tanzu Application Service For Vms
2.6.18 / 2.7.11+
CRITICAL 9.8
CVE-2020-3952 KEVEPSS 90%
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does no…
Vcenter Server
Mitigation only
HIGH 7.8
CVE-2020-3950 KEVEPSS 7%
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4…
Fusion
5.4.0 / 11.0.1+
HIGH 8.8
CVE-2020-3947
VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of th…
Fusion
11.5.2 / 15.5.2+
HIGH 7.8
CVE-2019-5543
For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Wi…
Horizon Client
5.3.0 / 11.0.0+
HIGH 7.8
CVE-2020-3948
Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escalation vulnerability…
Fusion
11.5.2 / 15.5.2+
MEDIUM 6.5
CVE-2020-5405EPSS 69%
Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitra…
Spring Cloud Config
2.1.7 / 2.2.2+
CRITICAL 9.8
CVE-2020-3943
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An u…
Vrealize Operations
6.6.1 / 6.7.1+
HIGH 8.6
CVE-2020-3944
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authenti…
Vrealize Operations
6.6.1 / 6.7.1+
HIGH 7.5
CVE-2020-3945
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incor…
Vrealize Operations
6.6.1 / 6.7.1+
MEDIUM 5.3
CVE-2020-5397
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc …
Spring Framework
5.2.3+
MEDIUM 5.9
CVE-2020-3940
VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.
Workspace One Boxer
1.2.1 / 1.3.2+
HIGH 7.5
CVE-2020-5398EPSS 88%
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable …
Spring Framework
5.0.16 / 5.1.13+
HIGH 7.0
CVE-2020-3941
The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual Machine where To…
Tools
11.0.0+
CRITICAL 9.8
CVE-2016-1000027EPSS 32%
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data…
Spring Framework
6.0.0+
HIGH 7.8
CVE-2019-5539
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerabil…
Horizon View Agent
7.5.4 / 7.10.1+
CRITICAL 9.8
CVE-2019-5544 KEVEPSS 97%
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Crit…
Horizon Daas
9.0.0.0+
HIGH 8.6
CVE-2019-5098
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can ca…
Workstation
No fix yet
CRITICAL 9.1
CVE-2019-5541
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network ad…
Workstation
11.5.1 / 15.5.1+
HIGH 7.7
CVE-2019-5542
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handler. Successful expl…
Fusion
11.5.1 / 15.5.1+
HIGH 7.7
CVE-2019-5540
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful expl…
Workstation
11.5.1 / 15.5.1+
MEDIUM 6.5
CVE-2019-5536
VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) c…
Fusion
11.5.0 / 15.5.0+
MEDIUM 5.9
CVE-2019-5537
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of…
Vcenter Server
Mitigation only
MEDIUM 5.9
CVE-2019-5538
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of…
Vcenter Server
Mitigation only