imPC@ndo IT

VMware vulnerabilities

956 CVE

CVE-2026-41712
High 7.5

Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users.

vmware spring_ai
0.00EPSS
CVE-2026-22744
High 7.5

In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG block without escaping characters.This issue …

vmware spring_ai
0.00EPSS
CVE-2026-22743
High 7.5

Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is passed as a filter expression key in Neo4jVectorFilterExpressionConverter of spring-ai-neo4j-store, doKey() em…

vmware spring_ai
0.00EPSS
CVE-2026-22753
High 7.5

Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be…

vmware spring_security
0.00EPSS
CVE-2026-41840
Medium 5.9

Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.

vmware spring_framework
0.00EPSS
CVE-2009-1143
High 7.0

An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).

vmware open-vm-tools
0.00EPSS
CVE-2024-22237
High 7.8

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain root access to the system.

vmware aria_operations_for_networks
0.00EPSS
CVE-2021-22007
Medium 5.5

The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information.

vmware cloud_foundation · vmware vcenter_server
0.00EPSS
CVE-2011-1787
Medium 6.9

Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest …

vmware esx · vmware esxi · vmware fusion · vmware player · and 1 more
0.00EPSS
CVE-2026-41727
Medium 6.5

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry t…

vmware spring_for_apache_kafka
0.00EPSS
CVE-2026-40980
Medium 6.5

In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

vmware spring_ai
0.00EPSS
CVE-2026-22741
Low 3.1

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the appl…

vmware spring_framework
0.00EPSS
CVE-2022-22964
High 7.8

VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file.

vmware horizon
0.00EPSS
CVE-2026-40966
Medium 5.9

In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryA…

vmware spring_ai
0.00EPSS
CVE-2022-31693
Medium 5.5

VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANIC in …

vmware tools
0.00EPSS
CVE-2025-22245
Medium 5.9

VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.

broadcom vmware_nsx · vmware cloud_foundation · vmware telco_cloud_infrastructure · vmware telco_cloud_platform
0.00EPSS
CVE-2021-22020
Medium 5.5

The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server.

vmware cloud_foundation · vmware vcenter_server
0.00EPSS
CVE-2024-22251
Medium 5.9

VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclos…

vmware fusion · vmware workstation
0.00EPSS
CVE-2023-20880
Medium 6.7

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

vmware aria_operations · vmware cloud_foundation
0.00EPSS
CVE-2024-22236
Low 3.3

In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded …

vmware spring_cloud_contract
0.00EPSS
CVE-2023-20859
Medium 5.5

In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.

vmware spring_cloud_config · vmware spring_cloud_vault · vmware spring_vault
0.00EPSS
CVE-2026-41002
High 7.2

The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclu…

vmware spring_cloud_config
0.00EPSS
CVE-2026-41713
High 8.2

A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across con…

vmware spring_ai
0.00EPSS
CVE-2026-22750
High 7.5

When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead. Note: The 4.2.x branch is no longer under open source support…

vmware spring_cloud_gateway
0.00EPSS
CVE-2023-34042
Medium 4.1

The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access to the file system. While there are no known exploits, this is an example of “CWE-732: Inc…

vmware spring_security
0.00EPSS