Vmware
vmware
958 CVEs • 195 products
Products (195)
Click to collapseToggle
Products (195)
Click to collapse
CVEs (958)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Netapp Vmware3Active Iq Unified Manager Oncommand InsightSpring FrameworkJun 17, 2026 Aug 20, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) c...Show more |
Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective. |
In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could le...Show more |
1Vmware 2Aria Automation Cloud FoundationJun 17, 2026 Jul 11, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write...Show more |
VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tas...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Jun 25, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition. |
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-...Show more |
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user man...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Jun 18, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileg...Show more |
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted ne...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Jun 18, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted ne...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 May 21, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 May 21, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the un...Show more |
1Vmware 4Cloud Foundation EsxiFusion+1 moreJun 17, 2026 May 21, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to c...Show more |
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able t...Show more |
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged informati...Show more |
VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploi...Show more |
VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the vir...Show more |
2Netapp Vmware2Active Iq Unified Manager Spring FrameworkJun 17, 2026 Mar 16, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open...Show more |
VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the instance. |