vmware

950 tracked vulnerabilities.

CVE-2025-41251 HIGH
VMware NSX/NSX-T/Cloud Foundation Unauthenticated Username Enumeration via Weak Password Recovery
Sep 29, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-41250 HIGH
VMware vCenter 8.0-8.0 U3g, 7.0-7.0 U3w - SMTP Header Injection via Scheduled Task Notifications
Sep 29, 2025
CVSS 8.5
EPSS 0.00
CVE-2025-41245 MEDIUM
VMware Aria Operations - Info Disclosure
Sep 29, 2025
CVSS 4.9
EPSS 0.00
CVE-2025-41244 HIGH KEV
VMware Aria Operations and VMware Tools - Local Privilege Escalation via SDMP
Sep 29, 2025
CVSS 7.8
EPSS 0.01
CVE-2025-41246 HIGH
VMware Tools for Windows - Privilege Escalation
Sep 29, 2025
CVSS 7.6
EPSS 0.00
CVE-2025-41249 HIGH
Spring Framework 5.3.0-5.3.44, 6.1.0-6.1.22, 6.2.0-6.2.10 - Improper Authorization via Annotation Detection Mechanism
Sep 16, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-41248 HIGH
Spring Security 6.4.0-6.4.9, 6.4.10-6.4.10, 6.5.0-6.5.4 - Authentication Bypass via Incorrect Annotation Resolution
Sep 16, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-41242 MEDIUM NUCLEI
Spring Framework 5.3.x-5.3.43 6.1.x-6.1.21 6.2.x-6.2.9 - Path Traversal via Static Resource Handling
Aug 18, 2025
CVSS 5.9
EPSS 0.05
CVE-2025-41241 MEDIUM
VMware vCenter 8.0-8.0 U3g, 7.0-7.0 U3v - Authenticated Denial of Service via Guest OS Customization API
Jul 29, 2025
CVSS 4.4
EPSS 0.00
CVE-2025-41240 CRITICAL
Bitnami Helm charts - Info Disclosure
Jul 24, 2025
CVSS 10.0
EPSS 0.01
CVE-2025-22227 MEDIUM
Reactor Netty HTTP Client - Credential Leak via Chained Redirects
Jul 16, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-41239 HIGH
VMware ESXi, Workstation, Fusion, VMware Tools - Info Disclosure
Jul 15, 2025
CVSS 7.1
EPSS 0.00
CVE-2025-41238 CRITICAL
VMware ESXi/Fusion/Workstation - Heap-Overflow
Jul 15, 2025
CVSS 9.3
EPSS 0.00
CVE-2025-41237 CRITICAL
VMware ESXi/Fusion/Workstation - Code Execution
Jul 15, 2025
CVSS 9.3
EPSS 0.00
CVE-2025-41236 CRITICAL
VMware ESXi, Workstation, and Fusion - RCE
Jul 15, 2025
CVSS 9.3
EPSS 0.00
CVE-2025-22242 MEDIUM
Salt 3006.x < 3006.12 and 3007.x < 3007.4 - Denial of Service via File Read Operation
Jun 13, 2025
CVSS 5.6
EPSS 0.00
CVE-2025-22241 MEDIUM
Salt 3006.x < 3006.12 and 3007.x < 3007.4 - Path Traversal in VirtKey Class
Jun 13, 2025
CVSS 5.6
EPSS 0.00
CVE-2025-22240 MEDIUM
Salt 3006.x < 3006.12 and 3007.x < 3007.4 - Arbitrary File Deletion via GitFS find_file Method
Jun 13, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-22239 HIGH
Salt 3006.0rc1-3006.11 and 3007.0-3007.3 - Arbitrary Event Injection via _minion_event Method
Jun 13, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-22238 MEDIUM
Salt 3006.0rc1-3006.11 and 3007.0-3007.3 - Path Traversal and Arbitrary File Write in Minion File Cache
Jun 13, 2025
CVSS 4.2
EPSS 0.00
CVE-2025-22237 MEDIUM
SaltStack <version> - Command Injection
Jun 13, 2025
CVSS 6.7
EPSS 0.00
CVE-2025-22236 HIGH
Salt 3007.0-3007.3 and 3006.0-3006.11 - Minion Event Bus Authorization Bypass
Jun 13, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-41234 MEDIUM
Spring Framework <6.0.5, 6.1.x, 6.2.x - RFD
Jun 12, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-41233 MEDIUM
VMware AVI Load Balancer - Authenticated SQL Injection
Jun 12, 2025
CVSS 6.8
EPSS 0.00
CVE-2025-22245 MEDIUM
VMware NSX 3.2-4.1.2.5 - Stored Cross-Site Scripting in Router Port
Jun 04, 2025
CVSS 5.9
EPSS 0.00