Vmware
vmware
958 CVEs • 195 products
Products (195)
Click to collapseToggle
Products (195)
Click to collapse
CVEs (958)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is insta...Show more |
VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inj...Show more |
1Vmware 2Cloud Foundation Nsx Data CenterJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root. |
ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy servic...Show more |
VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges...Show more |
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd servic...Show more |
1Vmware 4Cloud Foundation EsxiFusion+1 moreJun 17, 2026 Feb 16, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as...Show more |
1Vmware 5Cloud Foundation EsxiFusion+2 moreJun 17, 2026 Feb 16, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code a...Show more |
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Found...Show more |
VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A mal...Show more |
2Oracle Vmware3Communications Cloud Native Core Console Communications Cloud Native Core Service Communication ProxySpring FrameworkJun 17, 2026 Jan 10, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to C...Show more |
1Vmware 4Cloud Foundation EsxiFusion+1 moreJun 17, 2026 Jan 4, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A maliciou...Show more |
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor au...Show more |
1Vmware 3Identity Manager Vrealize AutomationWorkspace One AccessJun 17, 2026 Dec 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary ori...Show more |
1Vmware 1Workspace One Uem Console Jun 17, 2026 Dec 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with...Show more |
1Vmware 1Spring Advanced Message Queuing Protocol Jun 17, 2026 Nov 30, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Er...Show more |
The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit t...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Nov 24, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive infor...Show more |
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a requ...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Nov 10, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit thi...Show more |