Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-22243 VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. Cloud Foundation 4.1.2.6 / 4.2.1.4+ Fix from $1,9502025-06-04 MEDIUM 6.9 CVE-2025-22244 VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation. Cloud Foundation 4.1.2.6 / 4.2.1.4+ Fix from $1,6002025-06-04 MEDIUM 5.9 CVE-2025-22245 VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. Cloud Foundation 4.1.2.6 / 4.2.1.4+ Fix from $1,6002025-06-04 HIGH 7.3 CVE-2025-41231 VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be abl… Cloud Foundation 4.5.2 / 5.2.1.2+ Fix from $1,9502025-05-20 HIGH 8.2 CVE-2025-22249 VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access to… Aria Automation after 5.2.1 Fix from $1,9502025-05-13 HIGH 8.2 CVE-2025-22224 KEV VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with … Esxi 17.6.3+ Fix from $1,9502025-03-04 HIGH 8.2 CVE-2025-22225 KEV VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write… Esxi Mitigation only Fix from $1,9502025-03-04 MEDIUM 6.0 CVE-2025-22226 KEV VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with adm… Esxi 13.6.3 / 17.6.3+ Fix from $1,6002025-03-04 CRITICAL 9.0 CVE-2025-22219 VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be abl… Aria Operations For Logs 8.18.3+ Fix from $2,3002025-01-30 MEDIUM 6.5 CVE-2025-22222 VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnera… Aria Operations 8.18.3+ Fix from $1,6002025-01-30 MEDIUM 5.4 CVE-2025-22220 VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network acces… Aria Operations For Logs 8.18.3+ Fix from $1,6002025-01-30 HIGH 7.7 CVE-2025-22218 VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to r… Aria Operations For Logs 8.18.3+ Fix from $1,9502025-01-30 HIGH 7.8 CVE-2024-38830 VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this v… Aria Operations 8.18.2+ Fix from $1,9502024-11-26 HIGH 7.8 CVE-2024-38831 VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malici… Aria Operations 8.18.2+ Fix from $1,9502024-11-26 MEDIUM 6.4 CVE-2024-38832 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject mal… Aria Operations 8.18.2+ Fix from $1,6002024-11-26 MEDIUM 5.4 CVE-2024-38833 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject ma… Aria Operations 8.18.2+ Fix from $1,6002024-11-26 MEDIUM 5.3 CVE-2024-38820 The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exc… Spring Framework 5.3.41 / 6.0.25+ Fix from $1,6002024-10-18 HIGH 8.8 CVE-2024-38814EPSS 15% An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator p… Vmware Hcx after 4.9.1 Fix from $1,9502024-10-16 CRITICAL 9.8 CVE-2024-38813 KEVEPSS 17% The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerabil… Cloud Foundation 5.2+ Fix from $2,3002024-09-17 CRITICAL 9.8 CVE-2024-38812 KEVEPSS 55% The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCen… Cloud Foundation 5.2+ Fix from $2,3002024-09-17 HIGH 7.8 CVE-2024-38811 VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with… Fusion 13.6+ Fix from $1,9502024-09-03 HIGH 7.5 CVE-2024-38810 Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective. Spring Security 6.3.2+ Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-37084EPSS 35% In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to wr… Spring Cloud Data Flow 2.11.4+ Fix from $1,9502024-07-25 HIGH 8.1 CVE-2024-22280 VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could e… Aria Automation 8.17.0+ Fix from $1,9502024-07-11 MEDIUM 5.4 CVE-2024-22277 VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availa… Cloud Director 4.7.2+ Fix from $1,6002024-07-04 HIGH 7.2 CVE-2024-37085 KEVEPSS 26% VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access… Cloud Foundation 5.2+ Fix from $1,9502024-06-25 MEDIUM 6.8 CVE-2024-37086 VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an exist… Cloud Foundation 5.2+ Fix from $1,6002024-06-25 MEDIUM 5.3 CVE-2024-37087 The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service… Cloud Foundation 5.2+ Fix from $1,6002024-06-25 CRITICAL 9.8 CVE-2024-37079 KEVEPSS 22% vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter … Cloud Foundation 5.2+ Fix from $2,3002024-06-18 CRITICAL 9.8 CVE-2024-37080EPSS 12% vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter … Vcenter Server Patch available Fix from $2,3002024-06-18