Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2025-22243
VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
Cloud Foundation
4.1.2.6 / 4.2.1.4+
MEDIUM 6.9
CVE-2025-22244
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.
Cloud Foundation
4.1.2.6 / 4.2.1.4+
MEDIUM 5.9
CVE-2025-22245
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.
Cloud Foundation
4.1.2.6 / 4.2.1.4+
HIGH 7.3
CVE-2025-41231
VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be abl…
Cloud Foundation
4.5.2 / 5.2.1.2+
HIGH 8.2
CVE-2025-22249
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access to…
Aria Automation
after 5.2.1
HIGH 8.2
CVE-2025-22224 KEV
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with …
Esxi
17.6.3+
HIGH 8.2
CVE-2025-22225 KEV
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write…
Esxi
Mitigation only
MEDIUM 6.0
CVE-2025-22226 KEV
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with adm…
Esxi
13.6.3 / 17.6.3+
CRITICAL 9.0
CVE-2025-22219
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be abl…
Aria Operations For Logs
8.18.3+
MEDIUM 6.5
CVE-2025-22222
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnera…
Aria Operations
8.18.3+
MEDIUM 5.4
CVE-2025-22220
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network acces…
Aria Operations For Logs
8.18.3+
HIGH 7.7
CVE-2025-22218
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to r…
Aria Operations For Logs
8.18.3+
HIGH 7.8
CVE-2024-38830
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this v…
Aria Operations
8.18.2+
HIGH 7.8
CVE-2024-38831
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malici…
Aria Operations
8.18.2+
MEDIUM 6.4
CVE-2024-38832
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject mal…
Aria Operations
8.18.2+
MEDIUM 5.4
CVE-2024-38833
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject ma…
Aria Operations
8.18.2+
MEDIUM 5.3
CVE-2024-38820
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exc…
Spring Framework
5.3.41 / 6.0.25+
HIGH 8.8
CVE-2024-38814EPSS 15%
An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A
malicious authenticated user with non-administrator p…
Vmware Hcx
after 4.9.1
CRITICAL 9.8
CVE-2024-38813 KEVEPSS 17%
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerabil…
Cloud Foundation
5.2+
CRITICAL 9.8
CVE-2024-38812 KEVEPSS 55%
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCen…
Cloud Foundation
5.2+
HIGH 7.8
CVE-2024-38811
VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with…
Fusion
13.6+
HIGH 7.5
CVE-2024-38810
Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.
Spring Security
6.3.2+
HIGH 8.8
CVE-2024-37084EPSS 35%
In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to wr…
Spring Cloud Data Flow
2.11.4+
HIGH 8.1
CVE-2024-22280
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could e…
Aria Automation
8.17.0+
MEDIUM 5.4
CVE-2024-22277
VMware Cloud Director Availability contains an HTML injection vulnerability.
A
malicious actor with network access to VMware Cloud Director
Availa…
Cloud Director
4.7.2+
HIGH 7.2
CVE-2024-37085 KEVEPSS 26%
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access…
Cloud Foundation
5.2+
MEDIUM 6.8
CVE-2024-37086
VMware ESXi contains an out-of-bounds read vulnerability. A
malicious actor with local administrative privileges on a virtual
machine with an exist…
Cloud Foundation
5.2+
MEDIUM 5.3
CVE-2024-37087
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service…
Cloud Foundation
5.2+
CRITICAL 9.8
CVE-2024-37079 KEVEPSS 22%
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter …
Cloud Foundation
5.2+
CRITICAL 9.8
CVE-2024-37080EPSS 12%
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter …
Vcenter Server
Patch available