Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2024-37081
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non…
Vcenter Server
5.2+
HIGH 7.2
CVE-2024-22274
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter app…
Cloud Foundation
5.1.1+
HIGH 7.8
CVE-2024-22273
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtu…
Cloud Foundation
5.1.1 / 13.5.1+
MEDIUM 6.0
CVE-2024-22270
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor …
Workstation
13.5.2 / 17.5.2+
MEDIUM 6.0
CVE-2024-22269
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative p…
Workstation
13.5.2 / 17.5.2+
MEDIUM 6.5
CVE-2024-22268
VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative acc…
Workstation
13.5.2 / 17.5.2+
HIGH 8.2
CVE-2024-22267
VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges…
Fusion
13.5.2 / 17.5.2+
HIGH 8.1
CVE-2024-22259
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform valid…
Spring Framework
5.3.33 / 6.0.18+
HIGH 8.2
CVE-2024-22254
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds writ…
Cloud Foundation
after 5.0
HIGH 7.1
CVE-2024-22255
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrativ…
Cloud Foundation
13.5.1 / 17.5.1+
MEDIUM 6.7
CVE-2024-22252
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative p…
Workstation
13.5.1 / 17.5.1+
MEDIUM 6.7
CVE-2024-22253
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative p…
Cloud Foundation
13.5.1 / 17.5.1+
MEDIUM 6.7
CVE-2024-22235
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can esca…
Aria Operations
8.16.0+
HIGH 7.4
CVE-2024-22234
In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it di…
Spring Security
6.1.7 / 6.2.2+
HIGH 7.8
CVE-2024-22237
Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl…
Aria Operations For Networks
after 6.12.0
HIGH 7.8
CVE-2024-22239
Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl…
Aria Operations For Networks
after 6.12.0
MEDIUM 5.5
CVE-2023-34042
The spring-security.xsd file inside the
spring-security-config jar is world writable which means that if it were
extracted it could be written by a…
Spring Security
5.8.7 / 6.0.7+
MEDIUM 5.5
CVE-2024-22236
In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnera…
Spring Cloud Contract
3.1.10 / 4.0.5+
HIGH 7.5
CVE-2024-22233
In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-servic…
Spring Framework
Mitigation only
HIGH 8.3
CVE-2023-34063
Aria Automation contains a Missing Access Control vulnerability.
An authenticated malicious actor may
exploit this vulnerability leading to unauth…
Aria Automation
Patch available
HIGH 7.8
CVE-2022-22942
The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processe…
Photon Os
Mitigation only
MEDIUM 6.5
CVE-2023-34055
In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may c…
Spring Boot
after 3.1.5
HIGH 7.5
CVE-2023-34053
In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service …
Spring Framework
6.0.14+
CRITICAL 9.8
CVE-2023-34060
VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from
an …
Cloud Director
10.5+
MEDIUM 6.1
CVE-2023-20886
VMware Workspace ONE UEM console contains an open redirect vulnerability.
A malicious actor may be able to redirect a victim to an attacker and ret…
Workspace One Uem
22.3.0.48 / 22.6.0.36+
HIGH 7.0
CVE-2023-34059
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able…
Open Vm Tools
after 12.3.0
HIGH 7.8
CVE-2023-34057
VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate pri…
Tools
12.1.1+
HIGH 7.5
CVE-2023-34058
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.v…
Open Vm Tools
12.3.5+
HIGH 7.5
CVE-2023-46120
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used …
Rabbitmq Java Client
5.18.0+
CRITICAL 9.8
CVE-2023-34048 KEVEPSS 99%
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to v…
Vcenter Server
after 5.5