← Back

Vmware

vmware

958 CVEs • 195 products

Products (195)

Click to collapse
Toggle
Workstation
workstation
Esxi
esxi
Fusion
fusion
Player
player
Esx
esx
Server
server
Ace
ace
Tools
tools
Spring Boot
spring_boot
Spring Ai
spring_ai
Horizon View
horizon_view
One Access
one_access
Virtualcenter
virtualcenter
Vmware Server
vmware_server
Esx Server
esx_server
Vma
vma
Open Vm Tools
open-vm-tools
View
view
Gsx Server
gsx_server
Movie Decoder
movie_decoder
Horizon
horizon
Rabbitmq
rabbitmq
Vmware Player
vmware_player
Vcenter
vcenter
Fusion Pro
fusion_pro
Airwatch
airwatch
Photon Os
photon_os
Horizon Daas
horizon_daas
Studio
studio
Vsphere
vsphere
Ixgben
ixgben
Ace 2
ace_2
Vmware Esx
vmware_esx
Vmware Esxi
vmware_esxi
Vix Api
vix_api
Tc Server
tc_server
Hyperic Hq
hyperic_hq
Vm Support
vm-support
Nsx Edge
nsx_edge
Vsphere Esxi
vsphere_esxi

CVEs (958)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
1Spring Data Rest
Jun 17, 2026
Sep 21, 2022
N/A· v4
3.7 LOW· v3
N/A· v2
Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying doma...Show more
Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.Show less
1Vmware
1Pinniped
Jun 17, 2026
Aug 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to co...Show more
An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially use their access token to continue their session beyond what proper use of their refresh token might allow.Show less
4Debian
FedoraprojectNetapp+1 more
4Debian Linux
FedoraOntap Select Deploy Administration Utility+1 more
Jun 17, 2026
Aug 23, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual m...Show more
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.Show less
1Vmware
2I40en
Ixgben
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 2.1.5.0...Show more
Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 2.1.5.0 may allow an authenticated user to potentially enable a denial of service via local access.Show less
1Vmware
1Vrealize Operations
Jun 17, 2026
Aug 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges.
1Vmware
1Vrealize Operations
Jun 17, 2026
Aug 10, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.
1Vmware
1Vrealize Operations
Jun 17, 2026
Aug 10, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation...Show more
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution.Show less
1Vmware
1Vrealize Operations
Jun 17, 2026
Aug 10, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.
1Vmware
1Workstation
Jun 17, 2026
Aug 10, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the dis...Show more
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the disclosure of user passwords of the remote server connected through VMware Workstation.Show less
1Vmware
3Identity Manager
Identity Manager ConnectorOne Access
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.
1Vmware
4Access Connector
Identity ManagerIdentity Manager Connector+1 more
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
1Vmware
4Access Connector
Identity ManagerIdentity Manager Connector+1 more
Jun 17, 2026
Aug 5, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction ma...Show more
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.Show less
1Vmware
4Access Connector
Identity ManagerIdentity Manager Connector+1 more
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files.
1Vmware
4Access Connector
Identity ManagerIdentity Manager Connector+1 more
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.
1Vmware
4Access Connector
Identity ManagerIdentity Manager Connector+1 more
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
1Vmware
4Access Connector
Identity ManagerIdentity Manager Connector+1 more
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.
1Vmware
4Access Connector
Identity ManagerIdentity Manager Connector+1 more
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.
1Vmware
4Access Connector
Identity ManagerIdentity Manager Connector+1 more
Jun 17, 2026
Aug 5, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.
1Vmware
4Access Connector
Identity ManagerIdentity Manager Connector+1 more
Jun 17, 2026
Aug 5, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain adm...Show more
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.Show less
4Amd
DebianFedoraproject+1 more
126A10 9600p Firmware
A10 9630p FirmwareA12 9700p Firmware+123 more
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.