Vmware
vmware
958 CVEs • 195 products
Products (195)
Click to collapseToggle
Products (195)
Click to collapse
CVEs (958)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Jul 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Serv...Show more |
VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts. |
VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations. |
5Debian FedoraprojectIntel+2 more129Core I3 6100 Firmware Core I3 6100e FirmwareCore I3 6100h Firmware+126 moreJun 17, 2026 Jul 12, 2022 N/A· v4 6.5 MEDIUM· v3 1.9 LOW· v2 Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack r...Show more |
1Vmware 1Spring Data Mongodb Jun 17, 2026 Jun 23, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input i...Show more |
1Vmware 1Spring Cloud Function Jun 17, 2026 Jun 21, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Funct...Show more |
VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information. |
5Debian FedoraprojectIntel+2 more7Debian Linux EsxiFedora+4 moreJun 17, 2026 Jun 15, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
5Debian FedoraprojectIntel+2 more7Debian Linux EsxiFedora+4 moreJun 17, 2026 Jun 15, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
5Debian FedoraprojectIntel+2 more7Debian Linux EsxiFedora+4 moreJun 17, 2026 Jun 15, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is inst...Show more |
1Vmware 4Cloud Foundation Identity ManagerVrealize Suite Lifecycle Manager+1 moreJun 17, 2026 May 20, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. |
1Vmware 5Cloud Foundation Identity ManagerVrealize Automation+2 moreJun 17, 2026 May 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain adm...Show more |
3Netapp OracleVmware3Active Iq Unified Manager Financial Services Crime And Compliance Management StudioSpring SecurityJun 17, 2026 May 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatc...Show more |
3Netapp OracleVmware3Active Iq Unified Manager Financial Services Crime And Compliance Management StudioSpring SecurityJun 17, 2026 May 19, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder...Show more |
3Netapp OracleVmware4Cloud Secure Agent Financial Services Crime And Compliance Management StudioOncommand Insight+1 moreJun 17, 2026 May 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. |
3Netapp OracleVmware6Active Iq Unified Manager Brocade San NavigatorCloud Secure Agent+3 moreJun 17, 2026 May 12, 2022 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servle...Show more |
An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would involve the malicious user changing the common name (CN) of their user ent...Show more |
3Netapp OracleVmware7Active Iq Unified Manager Cloud Secure AgentMetrocluster Tiebreaker+4 moreJun 17, 2026 Apr 14, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it...Show more |
An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider may be able to exploit a remote code execution vulnerability to gain access to the server. |