58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-22983 | MED 5.9 | vmware workstation VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the disclosure of user passwords of the remote | 0.3% | — |
| CVE-2022-22982 | HIGH 7.5 | vmware cloud_foundation The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service. | 1.0% | — |
| CVE-2022-22980 | CRIT 9.8 | vmware spring_data_mongodb A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized. | 17.8% | — |
| CVE-2022-22979 | HIGH 7.5 | vmware spring_cloud_function In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework. | 1.4% | — |
| CVE-2022-22978 | CRIT 9.8 | netapp active_iq_unified_manager In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression a | 12.4% | — |
| CVE-2022-22977 | HIGH 7.1 | vmware tools VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to | 0.8% | — |
| CVE-2022-22976 | MED 5.3 | netapp active_iq_unified_manager Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to | 2.3% | — |
| CVE-2022-22975 | MED 6.6 | vmware pinniped An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would involve the malicious user changing the common name (CN) of their user entry on the LDAP or AD server to include s | 1.0% | — |
| CVE-2022-22973 | HIGH 7.8 | vmware cloud_foundation VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | 2.4% | — |
| CVE-2022-22972 | CRIT 9.8 | vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to a | 56.3% | — |
| CVE-2022-22971 | MED 6.5 | netapp cloud_secure_agent In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | 3.2% | — |
| CVE-2022-22970 | MED 5.3 | netapp active_iq_unified_manager In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | 2.0% | — |
| CVE-2022-22968 | MED 5.3 | netapp active_iq_unified_manager In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower cas | 5.7% | — |
| CVE-2022-22966 | HIGH 7.2 | vmware vcloud_director An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider may be able to exploit a remote code execution vulnerability to gain access to the server. | 6.6% | — |
| CVE-2022-22964 | HIGH 7.8 | vmware horizon VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file. | 0.2% | — |
| CVE-2022-22962 | HIGH 7.8 | vmware horizon VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file. | 0.3% | — |
| CVE-2022-22961 | MED 5.3 | vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation | 0.8% | — |
| CVE-2022-22959 | MED 4.3 | vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI. | 0.5% | — |
| CVE-2022-22958 | HIGH 7.2 | vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malici | 3.1% | — |
| CVE-2022-22957 | HIGH 7.2 | vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malici | 23.9% | — |
| CVE-2022-22956 | CRIT 9.8 | vmware identity_manager VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authent | 49.8% | — |
| CVE-2022-22955 | CRIT 9.8 | vmware identity_manager VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authent | 7.9% | — |
| CVE-2022-22953 | MED 6.5 | vmware vmware_hcx VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information. | 0.8% | — |
| CVE-2022-22952 | CRIT 9.1 | vmware carbon_black_app_control VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface m | 1.5% | — |
| CVE-2022-22951 | CRIT 9.1 | vmware carbon_black_app_control VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App | 20.3% | — |