Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2023-20878 VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and … Cloud Foundation after 4.5 Fix from $1,9502023-05-12 MEDIUM 6.7 CVE-2023-20879 VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations a… Cloud Foundation after 4.5 Fix from $1,6002023-05-12 MEDIUM 6.7 CVE-2023-20880 VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate p… Aria Operations 8.12.0+ Fix from $1,6002023-05-12 HIGH 8.2 CVE-2023-20869 VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing h… Fusion 13.0.2 / 17.0.2+ Fix from $1,9502023-04-25 MEDIUM 6.0 CVE-2023-20870 VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with th… Fusion 13.0.2 / 17.0.2+ Fix from $1,6002023-04-25 HIGH 8.8 CVE-2023-20872 VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. Fusion Mitigation only Fix from $1,9502023-04-25 HIGH 7.8 CVE-2023-20871 VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate … Fusion 13.0.2+ Fix from $1,9502023-04-25 HIGH 7.5 CVE-2023-29552 KEVEPSS 66% The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacke… Esxi 7.0+ Fix from $1,9502023-04-25 CRITICAL 9.8 CVE-2023-20864EPSS 70% VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Oper… Aria Operations For Logs 8.12.0+ Fix from $2,3002023-04-20 CRITICAL 9.8 CVE-2023-20873 In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susc… Spring Boot 2.5.15 / 2.6.14+ Fix from $2,3002023-04-20 HIGH 7.2 CVE-2023-20865 VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operation… Aria Operations For Logs 8.12.0+ Fix from $1,9502023-04-20 MEDIUM 6.3 CVE-2023-20862 In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not prop… Spring Security 5.7.8 / 5.8.3+ Fix from $1,6002023-04-19 MEDIUM 6.5 CVE-2023-20866 In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to thos… Spring Session Mitigation only Fix from $1,6002023-04-13 MEDIUM 6.5 CVE-2023-20863 In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression … Spring Framework 5.2.24 / 5.3.27+ Fix from $1,6002023-04-13 HIGH 7.5 CVE-2023-20860 Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher … Spring Framework 5.3.26 / 6.0.7+ Fix from $1,9502023-03-27 MEDIUM 6.5 CVE-2023-20861 In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user… Spring Framework after 6.0.6 Fix from $1,6002023-03-23 MEDIUM 5.5 CVE-2023-20859 In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sen… Spring Cloud Config 2.3.3 / 3.0.2+ Fix from $1,6002023-03-23 MEDIUM 6.8 CVE-2023-20857 VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass… Workspace One Content 23.02+ Fix from $1,6002023-02-28 HIGH 8.8 CVE-2023-20855 VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orche… Vrealize Automation 8.11.1+ Fix from $1,9502023-02-22 HIGH 7.2 CVE-2023-20858EPSS 17% VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious … Carbon Black App Control 8.7.8 / 8.8.6+ Fix from $1,9502023-02-22 HIGH 7.8 CVE-2022-36416 Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.13 may allow an authenticated us… Ixgben 1.10.0.13+ Fix from $1,9502023-02-16 MEDIUM 5.5 CVE-2022-36797 Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.1 may allow an authenticated use… Ixgben 1.10.0.1+ Fix from $1,6002023-02-16 HIGH 8.4 CVE-2023-20854 VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploi… Workstation Patch available Fix from $1,9502023-02-03 HIGH 8.8 CVE-2023-20856 VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of th… Vrealize Operations after 8.6.4 Fix from $1,9502023-02-01 HIGH 7.5 CVE-2022-31710 vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrust… Vrealize Log Insight 8.10.2+ Fix from $1,9502023-01-26 MEDIUM 5.3 CVE-2022-31711EPSS 22% VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and applicatio… Vrealize Log Insight 8.10.2+ Fix from $1,6002023-01-26 CRITICAL 9.8 CVE-2022-31704EPSS 81% The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive f… Vrealize Log Insight 8.10.2+ Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-31706EPSS 87% The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system… Vrealize Log Insight 8.10.2+ Fix from $2,3002023-01-26 HIGH 7.2 CVE-2022-31707 vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important sev… Vrealize Operations 8.6.4.20823815+ Fix from $1,9502022-12-16 CRITICAL 9.8 CVE-2022-31702 vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the… Vrealize Network Insight Patch available Fix from $2,3002022-12-14