Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.2
CVE-2023-20878
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and …
Cloud Foundation
after 4.5
MEDIUM 6.7
CVE-2023-20879
VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations a…
Cloud Foundation
after 4.5
MEDIUM 6.7
CVE-2023-20880
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate p…
Aria Operations
8.12.0+
HIGH 8.2
CVE-2023-20869
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing h…
Fusion
13.0.2 / 17.0.2+
MEDIUM 6.0
CVE-2023-20870
VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with th…
Fusion
13.0.2 / 17.0.2+
HIGH 8.8
CVE-2023-20872
VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
Fusion
Mitigation only
HIGH 7.8
CVE-2023-20871
VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate …
Fusion
13.0.2+
HIGH 7.5
CVE-2023-29552 KEVEPSS 66%
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacke…
Esxi
7.0+
CRITICAL 9.8
CVE-2023-20864EPSS 70%
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Oper…
Aria Operations For Logs
8.12.0+
CRITICAL 9.8
CVE-2023-20873
In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susc…
Spring Boot
2.5.15 / 2.6.14+
HIGH 7.2
CVE-2023-20865
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operation…
Aria Operations For Logs
8.12.0+
MEDIUM 6.3
CVE-2023-20862
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not prop…
Spring Security
5.7.8 / 5.8.3+
MEDIUM 6.5
CVE-2023-20866
In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to thos…
Spring Session
Mitigation only
MEDIUM 6.5
CVE-2023-20863
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression …
Spring Framework
5.2.24 / 5.3.27+
HIGH 7.5
CVE-2023-20860
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher …
Spring Framework
5.3.26 / 6.0.7+
MEDIUM 6.5
CVE-2023-20861
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user…
Spring Framework
after 6.0.6
MEDIUM 5.5
CVE-2023-20859
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sen…
Spring Cloud Config
2.3.3 / 3.0.2+
MEDIUM 6.8
CVE-2023-20857
VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass…
Workspace One Content
23.02+
HIGH 8.8
CVE-2023-20855
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orche…
Vrealize Automation
8.11.1+
HIGH 7.2
CVE-2023-20858EPSS 17%
VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious …
Carbon Black App Control
8.7.8 / 8.8.6+
HIGH 7.8
CVE-2022-36416
Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.13 may allow an authenticated us…
Ixgben
1.10.0.13+
MEDIUM 5.5
CVE-2022-36797
Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.1 may allow an authenticated use…
Ixgben
1.10.0.1+
HIGH 8.4
CVE-2023-20854
VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploi…
Workstation
Patch available
HIGH 8.8
CVE-2023-20856
VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of th…
Vrealize Operations
after 8.6.4
HIGH 7.5
CVE-2022-31710
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrust…
Vrealize Log Insight
8.10.2+
MEDIUM 5.3
CVE-2022-31711EPSS 22%
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and applicatio…
Vrealize Log Insight
8.10.2+
CRITICAL 9.8
CVE-2022-31704EPSS 81%
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive f…
Vrealize Log Insight
8.10.2+
CRITICAL 9.8
CVE-2022-31706EPSS 87%
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system…
Vrealize Log Insight
8.10.2+
HIGH 7.2
CVE-2022-31707
vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important sev…
Vrealize Operations
8.6.4.20823815+
CRITICAL 9.8
CVE-2022-31702
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the…
Vrealize Network Insight
Patch available