vmware

950 tracked vulnerabilities.

CVE-2021-22057 HIGH
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 - Authentication Bypass
Dec 20, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-22056 HIGH
VMware Workspace ONE Access and Identity Manager - Server-Side Request Forgery
Dec 20, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-22054 HIGH KEVNUCLEI
VMware Workspace ONE UEM Console SSRF (20.0.8-20.0.8.36, 20.11.0-20.11.0.39, 21.2.0-21.2.0.26, 21.5.0-21.5.0.36)
Dec 17, 2021
CVSS 7.5
EPSS 0.94
CVE-2021-22095 MEDIUM
Spring AMQP 2.2.0-2.2.19 and 2.3.0-2.3.11 - Denial of Service via Large Message Body Deserialization
Nov 30, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-22049 CRITICAL
VMware vCenter Server - Server-Side Request Forgery in vSAN Web Client Plugin
Nov 24, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-21980 HIGH
vSphere Web Client - Info Disclosure
Nov 24, 2021
CVSS 7.5
EPSS 0.07
CVE-2021-22053 HIGH NUCLEI
Spring Cloud Netflix Hystrix Dashboard - Remote Code Execution via Request URI Path SpringEL Injection
Nov 19, 2021
CVSS 8.8
EPSS 0.90
CVE-2021-22048 HIGH
VMware Cloud Foundation >=3.0 <3.10.2.2 - Privilege Escalation via IWA Authentication Mechanism
Nov 10, 2021
CVSS 8.8
EPSS 0.01
CVE-2021-22051 MEDIUM
Spring Cloud Gateway < 2.2.10 and 3.0.0-3.0.5 - Incorrect Authorization
Nov 08, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-22038 HIGH
Windows Uninstaller - Privilege Escalation
Oct 29, 2021
CVSS 8.8
EPSS 0.01
CVE-2021-22037 HIGH
VMware InstallBuilder < 21.6.0 - Path Interception by Search Order Hijacking via reg.exe Command
Oct 29, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-22097 MEDIUM
Spring AMQP 2.2.0-2.2.18 and 2.3.0-2.3.10 - Denial of Service via Malicious Dictionary Deserialization
Oct 28, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-22096 MEDIUM
Spring Framework <5.3.11-<5.2.18 - Info Disclosure
Oct 28, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22047 MEDIUM
Spring Data REST 3.4.0-3.4.13 and 3.5.0-3.5.5 - Exposure of Sensitive Information via Unauthorized URI Access
Oct 28, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-22044 HIGH
Spring Cloud OpenFeign 2.2.0-2.2.9 and 3.0.0-3.0.4 - Unintended Endpoint Exposure via Type-Level RequestMapping
Oct 28, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-22034 HIGH
VMware vRealize Operations Tenant App < 8.6 - Information Disclosure
Oct 21, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-22036 MEDIUM
VMware vRealize Orchestrator 8.0-8.5 - Open Redirect and Sensitive Information Exposure via Improper Path Handling
Oct 13, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-22035 MEDIUM
VMware vRealize Log Insight 8.0.0-8.5.0 - Authenticated CSV Injection via Interactive Analytics Export
Oct 13, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-22033 LOW
VMware vRealize Operations < 8.6.0 - Server-Side Request Forgery
Oct 13, 2021
CVSS 2.7
EPSS 0.00
CVE-2021-22020 MEDIUM
VMware Cloud Foundation >=3.0 <3.10.2.2 - Denial of Service in Analytics Service
Sep 23, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-22019 HIGH
VMware Cloud Foundation >=3.0 <3.10.2.2 - Denial of Service via VAPI JSONRPC Message
Sep 23, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-22018 MEDIUM
VMware Cloud Foundation 4.0-4.3.0 - Arbitrary File Deletion in vSphere Life-cycle Manager Plug-in
Sep 23, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-22017 MEDIUM KEVNUCLEI
VMware vCenter Server - Server-Side Request Forgery via URI Normalization Bypass
Sep 23, 2021
CVSS 5.3
EPSS 0.75
CVE-2021-22016 MEDIUM
VMware Cloud Foundation 3.0-5.0 and vCenter Server - Reflected Cross-Site Scripting
Sep 23, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-22015 HIGH
VMware Cloud Foundation 3.0-5.0 and vCenter Server - Local Privilege Escalation via Improper File Permissions
Sep 23, 2021
CVSS 7.8
EPSS 0.02