imPC@ndo IT

VMware vulnerabilities

956 CVE

CVE-2023-20879
Medium 6.7

VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system.

vmware cloud_foundation · vmware vrealize_operations
0.00EPSS
CVE-2026-40974
Medium 5.0

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19),…

vmware spring_boot
0.00EPSS
CVE-2022-36797
Low 3.3

Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.1 may allow an authenticated user to potentially enable denial of service via local access.

vmware ixgben
0.00EPSS
CVE-2024-38830
High 7.8

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations.

vmware aria_operations · vmware cloud_foundation
0.00EPSS
CVE-2026-41852
Low 3.7

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Sp…

vmware spring_framework
0.00EPSS
CVE-2023-34043
Medium 6.7

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

vmware aria_operations · vmware cloud_foundation
0.00EPSS
CVE-2026-41008
Medium 6.1

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, w…

broadcom spring_authorization_server · vmware spring_security
0.00EPSS
CVE-2026-41838
Medium 4.8

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.…

vmware spring_framework
0.00EPSS
CVE-2026-40968
Medium 4.2

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escal…

vmware spring_grpc
0.00EPSS
CVE-2026-41004
Medium 4.4

When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Clou…

vmware spring_cloud_config
0.00EPSS
CVE-2026-41847
Medium 4.8

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

vmware spring_framework
0.00EPSS
CVE-2025-41231
High 7.3

VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.

vmware cloud_foundation
0.00EPSS
CVE-2024-22273
High 8.1

The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or e…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware workstation
0.00EPSS
CVE-2023-34045
Medium 6.6

VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A mal…

vmware fusion
0.00EPSS
CVE-2026-41845
High 7.1

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 …

vmware spring_framework
0.00EPSS
CVE-2026-40971
Medium 5.0

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.

vmware spring_boot
0.00EPSS
CVE-2026-41846
Medium 5.9

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected ver…

vmware spring_framework
0.00EPSS
CVE-2026-41694
Low 3.7

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affe…

vmware spring_security
0.00EPSS
CVE-2026-40973
High 7.0

A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attac…

vmware spring_boot
0.00EPSS
CVE-2026-40970
Medium 5.0

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

vmware spring_boot
0.00EPSS
CVE-2026-41844
Medium 4.2

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected ver…

vmware spring_framework
0.00EPSS
CVE-2026-41714
Medium 4.0

Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: Spring AMQP 4.0.0…

vmware spring_advanced_message_queuing_protocol
0.00EPSS
CVE-2022-31697
Medium 5.5

The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can acces…

vmware cloud_foundation · vmware vcenter_server
0.00EPSS
CVE-2023-34046
Medium 6.7

VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrad…

vmware fusion
0.00EPSS
CVE-2026-22751
Medium 4.8

Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.…

vmware spring_security
0.00EPSS