58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
VMware vulnerabilities
1041 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-4930 | MED 5.4 | vmware airwatch VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Successful exploitation of this issue could result in an unsuspecting AWC user being red | 0.9% | — |
| CVE-2021-22016 | MED 6.1 | vmware cloud_foundation The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link. | 0.9% | — |
| CVE-2019-5542 | HIGH 7.7 | vmware fusion VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition | 0.9% | — |
| CVE-2006-5990 | MED 4.0 | vmware virtualcenter VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify the server's X.509 certificate when creating an SSL session, which allows remote m | 0.9% | — |
| CVE-2022-31689 | CRIT 9.8 | vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token. | 0.9% | — |
| CVE-2022-31687 | CRIT 9.8 | vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | 0.9% | — |
| CVE-2017-8044 | MED 6.1 | vmware single_sign-on_for_pivotal_cloud_foundry In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks. | 0.9% | — |
| CVE-2017-8041 | MED 6.1 | vmware single_sign-on_for_pivotal_cloud_foundry In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name. | 0.9% | — |
| CVE-2022-38650 | CRIT 10.0 | vmware hyperic_server A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the pr | 0.9% | — |
| CVE-2006-3547 | MED 5.5 | vmware player EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying tha | 0.9% | — |
| CVE-2023-20872 | HIGH 8.8 | vmware fusion VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. | 0.9% | — |
| CVE-2021-22113 | MED 5.3 | vmware spring_cloud_netflix_zuul Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spri | 0.9% | — |
| CVE-2021-22060 | MED 4.3 | oracle communications_cloud_native_core_console In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against addi | 0.8% | — |
| CVE-2022-22961 | MED 5.3 | vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation | 0.8% | — |
| CVE-2017-4917 | CRIT 9.8 | vmware vsphere_data_protection VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained. | 0.8% | — |
| CVE-2015-2344 | MED 5.4 | vmware vrealize_automation Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 0.8% | — |
| CVE-2020-3982 | HIGH 7.7 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI de | 0.8% | — |
| CVE-2018-11076 | MED 6.5 | dell emc_avamar Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked i | 0.8% | — |
| CVE-2017-4951 | HIGH 8.8 | vmware airwatch VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their device | 0.8% | — |
| CVE-2016-2075 | MED 5.4 | vmware vrealize_business_advanced_and_enterprise Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 0.8% | — |
| CVE-2022-38652 | CRIT 9.9 | vmware hyperic_agent A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with | 0.8% | — |
| CVE-2007-4497 | MED 5.5 | canonical ubuntu_linux Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server be | 0.8% | — |
| CVE-2015-1044 | LOW 3.3 | vmware esxi vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allows attackers to cause a host OS denial of service via unspecified vectors. | 0.8% | — |
| CVE-2026-40982 | CRIT 9.1 | vmware spring_cloud_config Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Sprin | 0.8% | — |
| CVE-2022-31708 | MED 4.9 | vmware vrealize_operations vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4. | 0.8% | — |