58.465 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
VMware vulnerabilities
1041 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-41702 | HIGH 7.8 | vmware fusion VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to roo | 0.1% | — |
| CVE-2026-22735 | LOW 2.6 | vmware spring_framework Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46. | 0.1% | — |
| CVE-2026-22751 | MED 4.8 | vmware spring_security Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4. | 0.1% | — |
| CVE-2023-34046 | MED 6.7 | vmware fusion VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrad | 0.1% | — |
| CVE-2026-41001 | MED 5.3 | vmware spring_boot Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a sym | 0.1% | — |
| CVE-2026-59297 | LOW 3.1 | vmware spring_cloud_function Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 | 0.1% | — |
| CVE-2026-40973 | HIGH 7.0 | vmware spring_boot A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attac | 0.1% | — |
| CVE-2022-31697 | MED 5.5 | vmware cloud_foundation The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can acces | 0.1% | — |
| CVE-2026-59292 | LOW 3.2 | vmware spring_integration PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 S | 0.1% | — |
| CVE-2026-47842 | MED 6.5 | vmware spring_security Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using a null (all-zero) initialization vector. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0 | 0.1% | — |
| CVE-2026-40977 | MED 4.7 | vmware spring_boot When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5. | 0.1% | — |
| CVE-2026-40979 | MED 6.1 | vmware spring_ai In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5) | 0.2% | — |
| CVE-2026-41004 | MED 4.4 | vmware spring_cloud_config When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Clou | 0.2% | — |
| CVE-2023-34045 | MED 6.6 | vmware fusion VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A mal | 0.2% | — |
| CVE-2024-22273 | HIGH 8.1 | vmware cloud_foundation The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or e | 0.2% | — |
| CVE-2026-41714 | MED 4.0 | vmware spring_advanced_message_queuing_protocol Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: Spring AMQP 4.0.0 | 0.2% | — |
| CVE-2026-59302 | LOW 3.1 | vmware spring_cloud_function Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | 0.2% | — |
| CVE-2025-41231 | HIGH 7.3 | vmware cloud_foundation VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information. | 0.2% | — |
| CVE-2026-59321 | MED 4.2 | vmware spring_integration A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREADING=null (not thread-safe, e.g. the Kotlin kts engine), concurrent message processing can corrupt engine-internal state, potentially le | 0.2% | — |
| CVE-2024-38830 | HIGH 7.8 | vmware aria_operations VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations. | 0.2% | — |
| CVE-2026-41694 | LOW 3.7 | vmware spring_security Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affe | 0.2% | — |
| CVE-2022-36797 | LOW 3.3 | vmware ixgben Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.1 may allow an authenticated user to potentially enable denial of service via local access. | 0.2% | — |
| CVE-2023-20879 | MED 6.7 | vmware cloud_foundation VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system. | 0.2% | — |
| CVE-2026-40992 | MED 5.0 | vmware spring_boot Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected versions: Spring Boot 4.0.0 th | 0.2% | — |
| CVE-2026-47825 | HIGH 8.6 | vmware spring_cloud_gateway Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spr | 0.2% | — |