imPC@ndo IT

VMware vulnerabilities

956 CVE

CVE-2026-22746
Low 3.7

Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypasse…

vmware spring_security
0.00EPSS
CVE-2024-22239
Medium 5.3

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access.

vmware aria_operations_for_networks
0.00EPSS
CVE-2026-41706
Medium 6.1

Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute …

vmware spring_security
0.00EPSS
CVE-2026-40990
Medium 5.7

OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Fu…

vmware spring_cloud_function
0.00EPSS
CVE-2026-40989
Medium 5.7

Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Function 4.2.x…

vmware spring_cloud_function
0.00EPSS
CVE-2020-4008
Low 3.6

The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited number o…

vmware carbon_black_cloud
0.00EPSS
CVE-2020-3957
High 7.0

VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Suc…

vmware fusion · vmware horizon_client · vmware remote_console
0.00EPSS
CVE-2022-31681
Medium 6.5

VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.

vmware cloud_foundation · vmware esxi
0.00EPSS
CVE-2026-41003
High 7.6

An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 t…

vmware spring_security
0.00EPSS
CVE-2023-34044
High 7.1

VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privi…

vmware fusion · vmware workstation
0.00EPSS
CVE-2023-34052
High 7.8

VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.

vmware aria_operations_for_logs
0.00EPSS
CVE-2026-22748
Medium 5.3

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator.This issue affects Spring…

vmware spring_security
0.00EPSS
CVE-2022-31699
Low 3.3

VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure.

vmware cloud_foundation · vmware esxi
0.00EPSS
CVE-2026-40969
Low 3.7

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attack…

vmware spring_grpc
0.00EPSS
CVE-2022-36416
Medium 4.4

Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.13 may allow an authenticated user to potentially enable escalation of privilege via local access.

vmware ixgben
0.00EPSS
CVE-2026-40993
High 7.3

An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verification or encryption …

vmware spring_security
0.00EPSS
CVE-2026-41730
Medium 5.3

Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14;…

vmware spring_data_rest
0.00EPSS
CVE-2026-41839
Medium 4.2

A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring Framework 7.0.0 throu…

vmware spring_framework
0.00EPSS
CVE-2024-22235
Medium 6.7

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

vmware aria_operations · vmware cloud_foundation
0.00EPSS
CVE-2024-37086
Medium 6.8

VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.

vmware cloud_foundation · vmware esxi
0.00EPSS
CVE-2023-34057
High 7.8

VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate privileges within the virtual machine.

vmware tools
0.00EPSS
CVE-2026-41837
Medium 5.3

Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 …

vmware spring_data_rest
0.00EPSS
CVE-2026-41700
High 8.1

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operation…

vmware spring_for_graphql
0.00EPSS
CVE-2022-21793
Medium 5.5

Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 2.1.5.0 may allow an authenticated user to poten…

vmware i40en · vmware ixgben
0.00EPSS
CVE-2026-41853
Medium 5.3

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

vmware spring_framework
0.00EPSS