Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2023-34045 VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation for the first time (the user n… Fusion 13.5+ Fix from $1,9502023-10-20 HIGH 7.0 CVE-2023-34046 VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (th… Fusion 13.5+ Fix from $1,9502023-10-20 MEDIUM 6.0 CVE-2023-34044 VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality … Workstation 13.5 / 17.5+ Fix from $1,6002023-10-20 HIGH 7.8 CVE-2023-34052 VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can tr… Aria Operations For Logs Patch available Fix from $1,9502023-10-20 CRITICAL 9.8 CVE-2023-34051EPSS 45% VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operat… Aria Operations For Logs Patch available Fix from $2,3002023-10-20 MEDIUM 6.7 CVE-2023-34043 VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can esca… Aria Operations 4.4+ Fix from $1,6002023-09-27 HIGH 7.5 CVE-2023-20900 A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E… Tools 10.3.26 / 12.3.0+ Fix from $1,9502023-08-31 CRITICAL 9.8 CVE-2023-34039EPSS 64% Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor … Aria Operations For Networks 6.11.0+ Fix from $2,3002023-08-29 HIGH 7.2 CVE-2023-20890EPSS 22% Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Ar… Aria Operations For Networks 6.11.0+ Fix from $1,9502023-08-29 HIGH 7.8 CVE-2023-34040 In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual c… Spring For Apache Kafka after 3.0.9 Fix from $1,9502023-08-24 MEDIUM 5.3 CVE-2023-34038 VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relat… Horizon Client Mitigation only Fix from $1,6002023-08-04 MEDIUM 5.3 CVE-2023-34037 VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requ… Horizon Client Mitigation only Fix from $1,6002023-08-04 MEDIUM 6.5 CVE-2023-20891 The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials … Isolation Segment 2.11.35 / 2.11.42+ Fix from $1,6002023-07-26 CRITICAL 9.8 CVE-2023-34034 Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebF… Spring Security 5.6.12 / 5.7.10+ Fix from $2,3002023-07-19 MEDIUM 5.3 CVE-2023-34035 Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration i… Spring Security 5.8.5 / 6.0.5+ Fix from $1,6002023-07-18 MEDIUM 5.3 CVE-2023-34036 Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers if they are n… Spring Hateoas 1.5.5 / 2.0.5+ Fix from $1,6002023-07-17 HIGH 7.5 CVE-2023-20899 VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the applicatio… Sd Wan Edge Firmware 4.5.2+ Fix from $1,9502023-07-06 HIGH 7.5 CVE-2023-20896 The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network a… Vcenter Server 7.0+ Fix from $1,9502023-06-22 CRITICAL 9.8 CVE-2023-20893 The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access… Vcenter Server 7.0+ Fix from $2,3002023-06-22 CRITICAL 9.8 CVE-2023-20894EPSS 34% The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network … Vcenter Server 7.0+ Fix from $2,3002023-06-22 CRITICAL 9.8 CVE-2023-20895 The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network acc… Vcenter Server 7.0+ Fix from $2,3002023-06-22 CRITICAL 9.8 CVE-2023-20892 The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A ma… Vcenter Server 7.0+ Fix from $2,3002023-06-22 CRITICAL 9.8 CVE-2023-20887 KEVEPSS 98% Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks… Aria Operations For Networks after 6.10.0 Fix from $2,3002023-06-07 HIGH 8.8 CVE-2023-20888EPSS 82% Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations… Vrealize Network Insight after 6.10.0 Fix from $1,9502023-06-07 HIGH 7.5 CVE-2023-20889EPSS 79% Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Ne… Vrealize Network Insight after 6.10.0 Fix from $1,9502023-06-07 MEDIUM 5.5 CVE-2022-31693 VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious act… Tools 12.1.5+ Fix from $1,6002023-06-07 MEDIUM 6.1 CVE-2023-20884 VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to… Identity Manager after 22.09.1.0 Fix from $1,6002023-05-30 HIGH 7.5 CVE-2023-20883 In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial… Spring Boot 2.5.14+ Fix from $1,9502023-05-26 CRITICAL 9.1 CVE-2023-31131 Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods… Greenplum Database 6.22.3+ Fix from $2,3002023-05-15 HIGH 8.8 CVE-2023-20877 VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execu… Cloud Foundation after 4.5 Fix from $1,9502023-05-12